# Logstash not applying correct system time to ingestion timestamp

**URL:** <https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884>\
**Category:** Logstash\
**Created:** [June 13, 2023, 2:39pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884 "2023-06-13T14:39:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anthony\_Zottola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anthony_zottola/32/122198_2.png) [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Post date:** [June 13, 2023, 2:39pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884/1 "2023-06-13T14:39:45Z")

</div>

Hello, I live in the NA East timezone so currently we are 4 hours behind UTC,  
I understand that logstash puts the @timestamp in UTC but it is putting in the wrong time.  
Logstash parsed a log at 10:30 am in my timezone (Which is 2:30 pm UTC)

```auto
"@timestamp" => 2023-06-13T10:29:59.000Z,

```

But as you can see it says it is 10:30 am UTC which is not correct as it is 4 hours behind.

When I put the date command into the server to see the time it shows:

```auto
Tue Jun 13 02:30:31 PM UTC 2023

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2023, 3:08pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884/2 "2023-06-13T15:08:45Z")

</div>

How are you creating the [@timestamp] field?

---

<div class="post-metadata">

**Author:** ![Anthony\_Zottola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anthony_zottola/32/122198_2.png) [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Post date:** [June 13, 2023, 3:14pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884/3 "2023-06-13T15:14:35Z")

</div>

It is automatically created by logstash itself.  
This is the conf file that is being run

```auto
input {
    syslog {
        port => 5014
    }
}
filter {
}

output {
    elasticsearch {
        hosts => ["localhost:9200"]
        user => "elastic"
        password => "changeme" 
        index => ["syslog"]
    } 
    stdout { 
        codec => rubydebug 
    }
}

```

---

<div class="post-metadata">

**Author:** ![Anthony\_Zottola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anthony_zottola/32/122198_2.png) [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Post date:** [June 14, 2023, 4:53pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884/4 "2023-06-14T16:53:50Z")

</div>

After doing more research and finding this: [Logstash Syslog @timestamp incorrect - #7 by BenB196](https://discuss.elastic.co/t/logstash-syslog-timestamp-incorrect/166658/7)

I fixed the issue by adding the timezone to my syslog input:

```auto
input {
    syslog {
        port => 5014
        timezone => "America/New_York"
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2023, 4:53pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884/5 "2023-07-12T16:53:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
