# Recalculate times?

**URL:** <https://discuss.elastic.co/t/recalculate-times/272680>\
**Category:** Logstash\
**Created:** [May 11, 2021, 10:48am UTC](https://discuss.elastic.co/t/recalculate-times/272680 "2021-05-11T10:48:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Post date:** [May 11, 2021, 10:48am UTC](https://discuss.elastic.co/t/recalculate-times/272680/1 "2021-05-11T10:48:52Z")

</div>

Hi,

Due to a number of reasons we have servers logging with UTC en servers logging with timestamps in CEST. In kibana/es I would like to see everything in CESt to easily connect the dots with events in clientdevices. Is there any way in which I can convert a timestamp in logstash from utc to CESt (with regard of summer/winter time)?

At this moment the top of my concerning filter looks like this:

```
mutate {
       strip => ["message"]
}
                    
dissect {
    mapping => {
          "message" => "ts: %{ts} %{+ts} | logLevel: %{log-level} | appId: %{app-id} | %{} | SID: %{session-id} | TN: %{transaction-id} | clientIp: %{client-ip} | userId: %{user-id} | apiType: %{} | api: %{api} | platform: %{platform} | %{additional-data}"
    }
}

mutate {
     strip => ["ts", "log-level", "app-id", "session-id", "transaction-id", "client-ip", "user-id", "api", "platform", "additional-data"]
}

```

Thnx in advance.

---

<div class="post-metadata">

**Author:** ![Tuckson](https://avatars.discourse-cdn.com/v4/letter/t/f14d63/32.png) [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Post date:** [May 11, 2021, 12:31pm UTC](https://discuss.elastic.co/t/recalculate-times/272680/2 "2021-05-11T12:31:22Z")

</div>

This does the simple trick

```auto
date {
    match => ["ts", "yyyy-MM-dd HH:mm:ss,SSS"]
    timezone => "UTC"
    target => "@timestamp"
    remove_field => ["ts"]
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 11, 2021, 4:03pm UTC](https://discuss.elastic.co/t/recalculate-times/272680/3 "2021-05-11T16:03:00Z")

</div>

> [@Tuckson](#):
>
> In kibana/es I would like to see everything in CESt to easily connect the dots with events in clientdevices.

elasticsearch and logstash always store timestamps as UTC. You can lie to them about what timezone your timestamps are in to force them to store timestamps in a different timezone. kibana will, by default, transform timestamps into the local timezone, respecting DST. If you want kibana to present timestamps in a different timezone then that is configurable.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2021, 4:03pm UTC](https://discuss.elastic.co/t/recalculate-times/272680/4 "2021-06-08T16:03:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
