# Set date time transformations from date filter

**URL:** <https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759>\
**Category:** Logstash\
**Created:** [June 13, 2018, 3:54pm UTC](https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759 "2018-06-13T15:54:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkaramol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkaramol/32/22610_2.png) [@pkaramol](https://discuss.elastic.co/u/pkaramol)\
**Post date:** [June 13, 2018, 3:54pm UTC](https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759/1 "2018-06-13T15:54:28Z")

</div>

Here is a (partial) syslog entry (ignore IP validity they have been scrambled):

```
Jun 15 00:51:19 139.133.7.190 (squid-1): src="172.16.0.51" src_port="49530" dst="122.355.89.1" dst_port="80" local_time="15/Jun/2015:00:51:19 +0300"`

```

Here is the way I am using `date` filter

```
  date {
    # target => "@timestamp"
    match => ["local_time", "dd/MMM/yyyy:HH:mm:ss +0300"]
    # local_time="21/Jun/2015:23:45:39 +0300"
    tag_on_failure => ["no_date_match"]
    timezone => "Europe/Athens"
  }

```

Can anyone explain why my document gets a `@timestamp` shifted by 3 hours?, i.e. `2015-06-14T21:51:19.000Z`

I just want to have in my `@timestamp` the **exact** value (without the `+0300` part of course) appearing in the `local_time` field!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2018, 4:07pm UTC](https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759/2 "2018-06-13T16:07:45Z")

</div>

The Elastic stack always stores times as UTC. You have specified a timezone of Europe/Athens, which is three hours ahead of UTC.

If you are using Kibana that will typically adjust things back to the browser's local timezone.

---

<div class="post-metadata">

**Author:** ![pkaramol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkaramol/32/22610_2.png) [@pkaramol](https://discuss.elastic.co/u/pkaramol)\
**Post date:** [June 13, 2018, 4:14pm UTC](https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759/3 "2018-06-13T16:14:42Z")

</div>

Removing the

```
    timezone => "Europe/Athens"

```

makes the document having correct `@timestamp` (which can be viewed via its `json` representation) but now `kibana` is the misleading one (3 hours ahead)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2018, 4:18pm UTC](https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759/4 "2018-06-13T16:18:45Z")

</div>

The Elastic stack stores times as UTC, regardless of which time zone you are in. If your logs have timestamps that are in Europe/Athens you should expect them to be three hours behind in elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2018, 4:18pm UTC](https://discuss.elastic.co/t/set-date-time-transformations-from-date-filter/135759/5 "2018-07-11T16:18:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
