# Problem with the time in elastic

**URL:** <https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810>\
**Category:** Elasticsearch\
**Created:** [August 24, 2022, 12:28pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810 "2022-08-24T12:28:36Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![yosi\_herschkovitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yosi_herschkovitz/32/110027_2.png) [@yosi\_herschkovitz](https://discuss.elastic.co/u/yosi_herschkovitz)\
**Post date:** [August 24, 2022, 12:28pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/1 "2022-08-24T12:28:36Z")

</div>

hi i have elasticsearch-7.10.1 and kibana-7.10.1 and filebeat-7.10.1  
and i cant configure the time for israel  
in the Discover i see the timestamp and log\_date are different.  
how i can fix that the both time are Will be the same time.  
thanks

 ![Screenshot 2022-08-24 151530](https://us1.discourse-cdn.com/elastic/original/3X/8/1/81441327abb2c346c7ea7ac6dfb8a8255faf499c.png)

---

<div class="post-metadata">

**Author:** ![yosi\_herschkovitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yosi_herschkovitz/32/110027_2.png) [@yosi\_herschkovitz](https://discuss.elastic.co/u/yosi_herschkovitz)\
**Post date:** [August 29, 2022, 7:33am UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/2 "2022-08-29T07:33:10Z")

</div>

some one?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 29, 2022, 7:44am UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/3 "2022-08-29T07:44:53Z")

</div>

Timestamps in Elasticsearch are always stored in UTC timezone. Kibana does by default translate the main timestamp to the local timezone, which I suspect is what you see in effect here. Please retrieve the raw JSON document and show it here.

---

<div class="post-metadata">

**Author:** ![yosi\_herschkovitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yosi_herschkovitz/32/110027_2.png) [@yosi\_herschkovitz](https://discuss.elastic.co/u/yosi_herschkovitz)\
**Post date:** [August 30, 2022, 5:49am UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/4 "2022-08-30T05:49:40Z")

</div>

{  
"\_index": "x-2022.08.28",  
"\_type": "\_doc",  
"\_id": "lDPX5YIBQlgtrhReqQ55",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"server\_name": "x",  
"agent": {  
"hostname": "ELKSVR",  
"name": "ELKSVR",  
"id": "cf92b3a0-145e-4cf5-8d06-570bce700b79",  
"type": "filebeat",  
"ephemeral\_id": "52236d9a-729d-456e-9cd8-c57308bec428",  
"version": "7.10.1"  
},  
"deal": "87",  
"run\_id": "3",  
"log": {  
"file": {  
"path": "x"  
},  
"offset": 10587478  
},  
"system\_name": "x",  
"log\_level": "Info",  
"message": "Finished:OK, with Warnings",  
"input": {  
"type": "log"  
},  
"@timestamp": "2022-08-28T22:04:46.000+03:00",  
"ecs": {  
"version": "1.6.0"  
},  
"log\_date": "08/28/2022 22:04:46",  
"stage\_name": "x",  
"host": {  
"hostname": "ELKSVR",  
"os": {  
"build": "14393.4886",  
"kernel": "x (rs1\_release.220104-1735)",  
"name": "Windows Server 2016 Standard",  
"family": "windows",  
"version": "10.0",  
"platform": "windows"  
},  
"ip": [  
"fe80::65ef:5422:fc24:a89f",  
"192.168.0.198",  
"fe80::5efe:c0a8:c6"  
],  
"name": "ELKSVR",  
"id": "6fd8c9ec-e901-422d-87fe-18fba7ca496a",  
"mac": [  
"00:15:5d:01:85:05",  
"00:00:00:00:00:00:00:e0"  
],  
"architecture": "x86\_64"  
},  
"fields": {  
"pipeline": "xxxxx",  
"index": "xxxxx"  
}  
},  
"fields": {  
"@timestamp": [  
"2022-08-28T19:04:46.000Z"  
],  
"log\_date": [  
"2022-08-28T22:04:46.000Z"  
]  
},  
"sort": [  
1661713486000  
]  
}

---

<div class="post-metadata">

**Author:** ![yosi\_herschkovitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yosi_herschkovitz/32/110027_2.png) [@yosi\_herschkovitz](https://discuss.elastic.co/u/yosi_herschkovitz)\
**Post date:** [August 31, 2022, 10:54am UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/5 "2022-08-31T10:54:04Z")

</div>

some one?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 31, 2022, 12:04pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/6 "2022-08-31T12:04:05Z")

</div>

> [@yosi\_herschkovitz](#):
>
> "@timestamp": [  
> "2022-08-28T19:04:46.000Z"  
> ],  
> "log\_date": [  
> "2022-08-28T22:04:46.000Z"

Those are indeed different times, what does they look in the document?

The difference in those times are `+0300`, but without knowing how they look in the source document before filebeat is not possible to know which one is wrong and why.

How does the source document looks like? How are you indexing your data, are you using any filebeat module or it is a custom log with a custom ingest pipeline?

---

<div class="post-metadata">

**Author:** ![yosi\_herschkovitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yosi_herschkovitz/32/110027_2.png) [@yosi\_herschkovitz](https://discuss.elastic.co/u/yosi_herschkovitz)\
**Post date:** [August 31, 2022, 2:04pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/7 "2022-08-31T14:04:05Z")

</div>

custom ingest pipeline  
i use Processors wite grok

[  
{  
"grok": {  
"field": "message",  
"patterns": [  
"%{DATESTAMP:log\_date}\t%{DATA:log\_level}\t%{DATA:stage\_name}\t%{DATA:server\_name}\t%{DATA:system\_name}\tDealCode %{NUMBER:deal}\tPPBRunID %{NUMBER:run\_id}\tDG %{NUMBER:dg}\tRunName %{DATA:runner\_name}\t\[\[\[%{DATA:message}\]\]\]",  
"%{DATESTAMP:log\_date}\t%{DATA:log\_level}\t%{DATA:stage\_name}\t%{DATA:server\_name}\t%{DATA:system\_name}\tDealCode %{NUMBER:deal}\tPPBRunID %{NUMBER:run\_id}\tDG %{NUMBER:dg}\t\t\[\[\[%{DATA:message}\]\]\]",  
"%{DATESTAMP:log\_date}\t%{DATA:log\_level}\t%{DATA:stage\_name}\t%{DATA:server\_name}\t%{DATA:system\_name}\tDealCode %{NUMBER:deal}\tPPBRunID %{NUMBER:run\_id}\t\t\t\[\[\[%{DATA:message}\]\]\]",  
"%{DATESTAMP:log\_date}\t%{DATA:log\_level}\t%{DATA:stage\_name}\t%{DATA:server\_name}\t%{DATA:system\_name}\tDealCode %{NUMBER:deal}\tPPBRunID %{NUMBER:run\_id}\t\tRunName %{DATA:runner\_name}\t\[\[\[%{DATA:message}\]\]\]"  
]  
}  
},  
{  
"date": {  
"field": "log\_date",  
"formats": [  
"MM/dd/yyyy HH:mm:ss"  
]  
}  
}  
]

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 31, 2022, 2:46pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/8 "2022-08-31T14:46:19Z")

</div>

You also need to share the raw message that filebeat is consuming, it is not possible to know what is the wrong date without seeing the original message.

But from your date filter your date string does not have any information about timezone, if your original date is in your local timezone, which is UTC + 0300, you need to specify this in your date processor, if you do not specify a timezone it will assume that the date string is already in UTC and this can lead to wrong times in Kibana.

It should be something like this:

```auto
    {
      "date" : {
        "field" : "log_date",
        "formats" : ["MM/dd/yyyy HH:mm:ss"],
        "timezone" : "Asia/Jerusalem
      }
    }

```

---

<div class="post-metadata">

**Author:** ![yosi\_herschkovitz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yosi_herschkovitz/32/110027_2.png) [@yosi\_herschkovitz](https://discuss.elastic.co/u/yosi_herschkovitz)\
**Post date:** [September 1, 2022, 2:04pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/9 "2022-09-01T14:04:12Z")

</div>

> [@leandrojmp](#):
>
> consuming

i dont understand , its configure like this  
{  
"date" : {  
"field" : "log\_date",  
"formats" : ["MM/dd/yyyy HH:mm:ss"],  
"timezone" : "Asia/Jerusalem  
}  
}

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 1, 2022, 3:08pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/10 "2022-09-01T15:08:42Z")

</div>

How are filebeat receiving the logs? It is reading from a file?

You need to shared the source message before you run the ingest pipeline, before filebeat reading it.

As I said, your date string does not have any information about the timezone, if your date string is in your local time, which is `Asia/Jerusalem`, you need to tell the date processer in the ingest pipeline to use this timezone, if you do not configure a timezone, this date will be interpreted as already being in UTC.

Did you change the date processor in your ingest pipeline added the timezone? Did the time difference still present?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2022, 3:09pm UTC](https://discuss.elastic.co/t/problem-with-the-time-in-elastic/312810/11 "2022-09-29T15:09:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
