# Logstash timestamp shift

**URL:** <https://discuss.elastic.co/t/logstash-timestamp-shift/330397>\
**Category:** Logstash\
**Created:** [April 20, 2023, 2:18pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397 "2023-04-20T14:18:40Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 20, 2023, 2:18pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/1 "2023-04-20T14:18:40Z")

</div>

Hi !

I came across a strange behavior while parsing a timestamp epoch style

```auto

    date {
    match => ["eventtime_ms","UNIX"]
    target => "[event][created]"
    timezone => "Etc/GMT+2"
    }
        date {
    match => ["eventtime_ms","UNIX"]
    target => "[event][created4]"
    timezone => "Etc/GMT+4"
    }

```

Using this 2 date filters i came across the same time while viewing in kibana ?

I do understand that Kibana can shit timezones automatically when viewing date types but the JSON view tells me that nothing is happening

```auto

   "event": {
      "created4": "2023-04-20T14:15:27.000Z",
      "created": "2023-04-20T14:15:27.000Z"

```

I think i'm missing something here ! What's the catch ?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 20, 2023, 2:32pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/2 "2023-04-20T14:32:36Z")

</div>

time is same. but it has TZ attached now.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 20, 2023, 2:33pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/3 "2023-04-20T14:33:41Z")

</div>

> [@elasticforme](#):
>
> time is same. but it has TZ attached now.

Where can i see that ?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 20, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/4 "2023-04-20T14:36:43Z")

</div>

put that in elasticsearch,  
create two pattern (data view) one with created4 and created.  
now draw graph and you will see difference

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2023, 3:56pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/5 "2023-04-20T15:56:58Z")

</div>

I would expect the date filter to ignore the timezone option when parsing UNIX or UNIX\_MS. Those are intervals since the epoch in GMT, so they convert to the same UTC time in every timezone.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 20, 2023, 4:02pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/6 "2023-04-20T16:02:18Z")

</div>

This imply that epoch is GMT by default, this makes sense !

This means that i have different timezones from thoses logs i have to shift myself from the [event][created] source with ISOXXXX format ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2023, 4:11pm UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/7 "2023-04-20T16:11:48Z")

</div>

If the source logs have a timezone offset on an epoch based timestamp then they are not actually UNIX or UNIX\_MS. You could parse them as that, then convert to a string, mutate+gsub to remove the "Z$", and then go through the date filter again with the timezone set.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 21, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/8 "2023-04-21T07:51:56Z")

</div>

I got you ! It's actually fortinet logs with nanoseconds precision.

Actually i'd like to know if grok is the best solution to substract char from a string since the timestamp i'm working with is nanosecond precision.

```auto
    grok {
        match => {
            eventtime => "(?<eventtime_ms>..........)"

        }

```

Since you suggested mutate + gsub to remove Zulu marking there is maybe a better solution...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2023, 7:52am UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397/9 "2023-05-19T07:52:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
