# \[Still Not Solved!\] Filebeat cannot recognize timezone in syslog

**URL:** <https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 29, 2019, 9:37am UTC](https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661 "2019-07-29T09:37:27Z")\
**Posts on this page:** 1\
**Showing post:** 20

<div class="post-metadata">

**Author:** ![cosloli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cosloli/32/51115_2.png) [@cosloli](https://discuss.elastic.co/u/cosloli)\
**Post date:** [July 30, 2019, 3:06am UTC](https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661/20 "2019-07-30T03:06:46Z")

</div>

I tried to enable `var.convert_timezone: true` in `{conf_path}/module.d/system` as I said in the question. And I thought it works.

Then I filtered the data from filebeat and found that some logs are in correct timestamp, some are not.

The logs in apache, mysql, and elastic server have a correct `@timestamp` value. While the logs in syslog, elasticsearch.log, es\_deprecation and es\_gc are incorrect.

I've also checked my \_ingest/pipeline and I don't think there's any problem in the syslog-pipeline.

```auto
"filebeat-7.2.0-system-syslog-pipeline" : {
    "processors" : [
      {
        "grok" : {
          "field" : "message",
          "patterns" : [
            """%{SYSLOGTIMESTAMP:system.syslog.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\[%{POSINT:process.pid:long}\])?: %{GREEDYMULTILINE:system.syslog.message}""",
            "%{SYSLOGTIMESTAMP:system.syslog.timestamp} %{GREEDYMULTILINE:system.syslog.message}",
            """%{TIMESTAMP_ISO8601:system.syslog.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\[%{POSINT:process.pid:long}\])?: %{GREEDYMULTILINE:system.syslog.message}"""
          ],
          "pattern_definitions" : {
            "GREEDYMULTILINE" : "(.|\n)*"
          },
          "ignore_missing" : true
        }
      },
      {
        "remove" : {
          "field" : "message"
        }
      },
      {
        "rename" : {
          "field" : "system.syslog.message",
          "target_field" : "message",
          "ignore_missing" : true
        }
      },
      {
        "date" : {
          "field" : "system.syslog.timestamp",
          "target_field" : "@timestamp",
          "formats" : [
            "MMM d HH:mm:ss",
            "MMM dd HH:mm:ss",
            "ISO8601"
          ],
          "ignore_failure" : true
        }
      },
      {
        "remove" : {
          "field" : "system.syslog.timestamp"
        }
      }
    ],
    "on_failure" : [
      {
        "set" : {
          "field" : "error.message",
          "value" : "{{ _ingest.on_failure_message }}"
        }
      }
    ],
    "description" : "Pipeline for parsing Syslog messages."
  }

```

---

_[View the full topic](https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661)._
