# Logstash date filter performs a timeshift of 3 hours

**URL:** <https://discuss.elastic.co/t/logstash-date-filter-performs-a-timeshift-of-3-hours/135704>\
**Category:** Logstash\
**Created:** [June 13, 2018, 11:33am UTC](https://discuss.elastic.co/t/logstash-date-filter-performs-a-timeshift-of-3-hours/135704 "2018-06-13T11:33:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkaramol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkaramol/32/22610_2.png) [@pkaramol](https://discuss.elastic.co/u/pkaramol)\
**Post date:** [June 13, 2018, 11:33am UTC](https://discuss.elastic.co/t/logstash-date-filter-performs-a-timeshift-of-3-hours/135704/1 "2018-06-13T11:33:33Z")

</div>

Filtering some `syslog` logs (which are actually stored in a file as follows):

```
grok {
  match => { 'message' => '%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}' }
  add_field => ['received_at', '%{@timestamp}']
  add_field => ['received_from', '%{syslog_hostname}']
  add_field => ['unix_time', '0']
}

```

And then adding timestamp (should match a `local_time` field):

```
  date {
    target => "@timestamp"
    match => ["local_time", "dd/MMM/yyyy:HH:mm:ss Z"]
    # local_time="21/Jun/2015:23:45:39 +0300"
    locale => "en_us"
    tag_on_failure => ["no_date_match"]
  }

```

Here is an example `local_time` field value from my original logs:

```
local_time="15/Jun/2015:00:51:19 +0300"

```

However, my documents end up having a timestamp of 3hours **behind** (i.e. earlier) compared to what is mentioned in `local_time`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2018, 11:56am UTC](https://discuss.elastic.co/t/logstash-date-filter-performs-a-timeshift-of-3-hours/135704/2 "2018-06-13T11:56:32Z")

</div>

elasticsearch stores times as UTC. If your logs are not UTC then you need to supply the timezone option to the date filter to tell it what timezone they are in.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2018, 11:56am UTC](https://discuss.elastic.co/t/logstash-date-filter-performs-a-timeshift-of-3-hours/135704/3 "2018-07-11T11:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
