# Show event times in the local time zone where the event happened

**URL:** <https://discuss.elastic.co/t/show-event-times-in-the-local-time-zone-where-the-event-happened/158726>\
**Category:** Kibana\
**Created:** [November 29, 2018, 9:56am UTC](https://discuss.elastic.co/t/show-event-times-in-the-local-time-zone-where-the-event-happened/158726 "2018-11-29T09:56:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jps-bfx](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jps-bfx/32/38230_2.png) [@jps-bfx](https://discuss.elastic.co/u/jps-bfx)\
**Post date:** [November 29, 2018, 9:56am UTC](https://discuss.elastic.co/t/show-event-times-in-the-local-time-zone-where-the-event-happened/158726/1 "2018-11-29T09:56:14Z")

</div>

Hi All,

I'm using the Elastic Stack to analyse application analytics from desktop software. Our application log files contain dates in ISO8601 format, in local time including the offset from UTC. I'm ingesting these via Logstash which of course gives me UTC timestamps that for most of the reporting I want to do will be fine.

However, in Kibana I would like to be able to visualise the _local_ time of day people are using our software, in their local time zone not mine. This is to help us understand work patterns in different parts of the world.

The options I've thought of are to store an additional time field on the documents which is in local time (i.e. add the offset manually when creating the field in Logstash), or add a timezone field in the documents and use a scripted field in Kibana to apply the stored timezone offset.

Does anyone have a recommendation about how to approach this?

Thanks,

J-P

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [November 29, 2018, 4:26pm UTC](https://discuss.elastic.co/t/show-event-times-in-the-local-time-zone-where-the-event-happened/158726/2 "2018-11-29T16:26:31Z")

</div>

Either of those approaches will probably work fine, but I'd recommend going with the first. If you can control the data ingestion, then it's almost always a better idea to do things like this during ingestion rather than after the fact with scripted fields, because the scripts will have to run on all queries that use the data, rather than simply pulling data from a document.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2018, 4:26pm UTC](https://discuss.elastic.co/t/show-event-times-in-the-local-time-zone-where-the-event-happened/158726/3 "2018-12-27T16:26:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
