# Logstash datetime timezone

**URL:** <https://discuss.elastic.co/t/logstash-datetime-timezone/117981>\
**Category:** Logstash\
**Created:** [February 1, 2018, 9:27am UTC](https://discuss.elastic.co/t/logstash-datetime-timezone/117981 "2018-02-01T09:27:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anuar\_Mukatov](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Anuar\_Mukatov](https://discuss.elastic.co/u/Anuar_Mukatov)\
**Post date:** [February 1, 2018, 9:27am UTC](https://discuss.elastic.co/t/logstash-datetime-timezone/117981/1 "2018-02-01T09:27:04Z")

</div>

Hello!  
How i can change datetime timezone?  
What i else not to tr, anything didn't help me.

> ```
> input {
> jdbc {
> jdbc_driver_library => "/etc/logstash/drivers/sqljdbc42.jar"
> jdbc_driver_class => "com.microsoft.sqlserver.jdbc.SQLServerDriver"
> jdbc_connection_string => "jdbc:sqlserver://server:1433;databasename=db"
> jdbc_user => "login"
> jdbc_password => "pass"
> statement => "SELECT m.*
> , mc.nameRu AS CategoryNameRu
> , mt.nameRu AS TypeNameRu
> , ms.nameRu AS SourceNameRu
> , p.Fio_Ru
> , s.RowName AS LoginName
> , pos.FullNameRu AS PositionNameRu
> FROM LOG_Messages m
> JOIN DIC_LOG_MESSAGE_SOURCE_TO_TYPE mst ON mst.id = m.refMessageSourceType
> JOIN DIC_LOG_MESSAGE_CATEGORY mc ON mc.id = mst.refMessageCategory
> JOIN DIC_LOG_MESSAGE_TYPE mt ON mt.id = mst.refMessageType
> JOIN DIC_LOG_MESSAGE_SOURCE ms ON ms.id = mst.refMessageSource
> LEFT JOIN ULS_Persons p ON p.id = m.refRecordCard
> LEFT JOIN LOG_SidIdentification s ON s.id = m.refSid
> LEFT JOIN ULS_SubdivisionPositions pos ON pos.id = m.refPosition
> ORDER BY id DESC"
> }
> }   
> filter {
> mutate {
> add_field => { "message" => "%{typenameru}" }
> }
> date {
> match => ["datetime", "YYYY-MM-dd HH:mm:ss.SSS"]
> timezone => "Etc/GMT-6"
> }
> }
> output {
> gelf{
> host => "0.0.0.0"
> port => 12231
> short_message => 'short_message'
> }
> stdout { codec => rubydebug}
> }
> 
> ```

It is my output from debug -

> ```
> {
> "sourcenameru" => "Задачи",
> "loginname" => "OrderPointStatement",
> "refrvsproperties" => nil,
> "refmessagesourcetype" => 542,
> "message" => "Действие",
> "positionnameru" => nil,
> "content" => "Start ParagraphExecutor.Execute",
> **"datetime" => 2018-02-01T09:00:00.463Z,**
> **"@timestamp" => 2018-02-01T15:00:00.463Z,**
> "refposition" => nil,
> "clientipaddress" => "",
> "refrecordcard" => nil,
> "@version" => "1",
> "id" => 14232235,
> "refarchive" => 50,
> "refsid" => 3726,
> "categorynameru" => "Информация",
> "typenameru" => "Действие",
> "fio_ru" => nil
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2018, 9:51am UTC](https://discuss.elastic.co/t/logstash-datetime-timezone/117981/2 "2018-02-01T09:51:03Z")

</div>

The date filter always produced a UTC timestamp. This is not configurable. You could however use a ruby filter to get whatever timezone you want, and examples of that have been posted in the past. I just don't understand why people bother.

---

<div class="post-metadata">

**Author:** ![ericohtake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericohtake/32/24539_2.png) [@ericohtake](https://discuss.elastic.co/u/ericohtake)\
**Post date:** [February 1, 2018, 10:29am UTC](https://discuss.elastic.co/t/logstash-datetime-timezone/117981/3 "2018-02-01T10:29:32Z")

</div>

Agreed!!  
You are already getting help here [Datetime from sql to Timestamp logstash](https://discuss.elastic.co/t/datetime-from-sql-to-timestamp-logstash/117594/18)

Why open a new thread? And read the docs, you asked questions that are answered there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2018, 10:29am UTC](https://discuss.elastic.co/t/logstash-datetime-timezone/117981/4 "2018-03-01T10:29:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
