But Kibana displays it as below with a 2 hour time difference after changing the timezone to America/Vancouver in Index management > advanced settings. Changing it to any other timezone just shifts the time but histogram remains 2 hours behind.
The time in the index should be UTC, but in your case, maybe the value is wrong. There is a delta of 2 hours Universal time vs RTC time in your system, so I wonder If RTC time is written into the index, assuming it is UTC time. That would explain the 2 hours delta. If the UTC time written is correct, also Kibana would display it correctly.
@matw If I change the timezone in kabana to UTC, the time is shown in UTC but now the delta increases to 4. Any clue what/where should I be looking for.
yes, changing timezone in Kibana won't help, you should take care that the time that is set in logstash and sent to ES is UTC. And not just the format of UTC, also the value has to be correct. If you index a value that's correct for another timezone as UTC time, you will get a gap. And I'm sure this is the case in your scenario. Have a look at the raw values of you ES data.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.