Below is the sample log message
<12>May 5 00:10:28 UDM,50c9676c6d24,udm-126.96.36.19938 kernel: [522844.682013] IN=br30 OUT=eth4 MAC=76:ac:b9:1e:f2:fc:dc:a6:32:eb:22:ac:08:00 SRC=192.168.3.53 DST=188.8.131.52 LEN=61 TOS=0x00 PREC=0x00 TTL=63 ID=61244 DF PROTO=UDP SPT=45838 DPT=53 LEN=41
But Kibana displays it as below with a 2 hour time difference after changing the timezone to America/Vancouver in Index management > advanced settings. Changing it to any other timezone just shifts the time but histogram remains 2 hours behind.
timezone of system
[root@sof-elk filebeat]# timedatectl Local time: Tue 2021-05-04 22:38:00 PDT Universal time: Wed 2021-05-05 05:38:00 UTC RTC time: Wed 2021-05-05 07:26:22 Time zone: America/Vancouver (PDT, -0700)
how can I fix this. Also logstash seems to make new index file in UTC