# Problems with date fields

**URL:** <https://discuss.elastic.co/t/problems-with-date-fields/119193>\
**Category:** Kibana\
**Created:** [February 9, 2018, 9:07am UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193 "2018-02-09T09:07:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dyabolik00](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@dyabolik00](https://discuss.elastic.co/u/dyabolik00)\
**Post date:** [February 9, 2018, 9:07am UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/1 "2018-02-09T09:07:00Z")

</div>

Hello,  
i have set up logstash to get logs from syslog palo alto.  
in kibana under discover i see thetimestamp like February 9th 2018, 10:00:54.000 and the datefileds like TimeLogged:February 9th 2018, 11:00:53.000  
The timestamp is right and kibana is configured to use Browsertimezone.  
I think the problem is that the date fields that logstash is reciving are already set with the right timezone (+1) and when i see it in discover kibana adds another +1. how can i configure kibana or logstash to set the corect timezone on the logs i recive?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 9, 2018, 10:52am UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/2 "2018-02-09T10:52:45Z")

</div>

The Logstash [date filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-timezone) allows to specify the timezone used for date parsing. By default, if the date/time does not contain any information about time offsets, it's interpreted as UTC.

---

<div class="post-metadata">

**Author:** ![dyabolik00](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@dyabolik00](https://discuss.elastic.co/u/dyabolik00)\
**Post date:** [February 9, 2018, 4:04pm UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/3 "2018-02-09T16:04:29Z")

</div>

Thanks! I have try but i cant get it right!  
here is my logstash conf  
input {  
syslog {  
port =\> "5514"  
type =\> "syslog"  
tags =\> ["PAN-OS\_syslog"]  
}  
}

```
filter {
    if "PAN-OS_syslog" in [tags] {

        # Log types are "TRAFFIC", "THREAT", "CONFIG", "SYSTEM" and "HIP-MATCH".

        # Traffic log fields: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/monitoring/syslog-field-descriptions#_41809
        if ([message] =~ /TRAFFIC/) {
            csv {
                source => "message"
                columns => [ 
                    "FUTURE_USE", "ReceiveTime", "SerialNumber", "Type", "Threat_ContentType", "FUTURE_USE",
                    "GeneratedTime", "SourceIP", "DestinationIP", "NATSourceIP", "NATDestinationIP", "RuleName",
                    "SourceUser", "DestinationUser", "Application", "VirtualSystem", "SourceZone", "DestinationZone",
                    "InboundInterface", "OutboundInterface", "LogForwardingProfile", "TimeLogged", "SessionID",
                    "RepeatCount", "SourcePort", "DestinationPort", "NATSourcePort", "NATDestinationPort", "Flags",
                    "Protocol", "Action", "Bytes", "BytesSent", "BytesReceived", "Packets", "StartTime", "ElapsedTime",
                    "URLCategory", "FUTURE_USE", "SequenceNumber", "ActionFlags", "SourceLocation", 
                    "DestinationLocation", "FUTURE_USE", "PacketsSent", "PacketsReceived", "SessionEndReason",
                    "DeviceGroupHierarchyLevel1", "DeviceGroupHierarchyLevel2", "DeviceGroupHierarchyLevel3",
                    "DeviceGroupHierarchyLevel4", "VirtualSystemName", "DeviceName", "ActionSource", "SourceVMUUID",
                    "DestinationVMUUID", "TunnelID_IMSI", "MonitorTag_IMEI", "ParentSessionID", "ParentStartTime",
                    "TunnelType" 
                ]
            }

            mutate {
                convert => ["Bytes", "integer"]
                convert => ["BytesReceived", "integer"]
                convert => ["BytesSent", "integer"]
                convert => ["ElapsedTime", "integer"]
                convert => ["GeoIP.dma_code", "integer"]
                convert => ["GeoIP.latitude", "float"]
                convert => ["GeoIP.longitude", "float"]
                convert => ["NATDestinationPort", "integer"]
                convert => ["NATSourcePort", "integer"]
                convert => ["Packets", "integer"]
                convert => ["PacketsReceived", "integer"]
                convert => ["PacketsSent", "integer"]
                convert => ["SequenceNumber", "integer"]
                

				add_tag => ["PAN-OS_traffic"]
            }
			date {
match => ["ReceiveTime" , UNIX, "%Y/%m/%d %H:%M:%S"]
timezone => "Europe/Rome"
}
			
        }
```

---

<div class="post-metadata">

**Author:** ![dyabolik00](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@dyabolik00](https://discuss.elastic.co/u/dyabolik00)\
**Post date:** [February 9, 2018, 4:06pm UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/4 "2018-02-09T16:06:33Z")

</div>

I have add the date part but the recivetime field is still +1 in kibana and the timestamp is right

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 11, 2018, 11:58am UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/5 "2018-02-11T11:58:29Z")

</div>

As an alternative to using the date filter, you can also set the `timezone` parameter on the [syslog input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html#plugins-inputs-syslog-timezone).

---

<div class="post-metadata">

**Author:** ![dyabolik00](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@dyabolik00](https://discuss.elastic.co/u/dyabolik00)\
**Post date:** [February 12, 2018, 6:50am UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/6 "2018-02-12T06:50:12Z")

</div>

Same result ☹  
Time ReceiveTime  
February 12th 2018, 07:48:35.000 February 12th 2018, 08:48:34.000

```
input {
    syslog {
        port => "5514"
        type => "syslog"
        timezone => "Europe/Rome"
        tags => ["PAN-OS_syslog"]
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2018, 6:50am UTC](https://discuss.elastic.co/t/problems-with-date-fields/119193/7 "2018-03-12T06:50:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
