Syslog date in ingest node pipeline ahead


I am experiencing a strange thing with the date in the syslog log in filebeat. I am using the default ingest node pipeline (logs-system.syslog-0.12.7) which creates a new timestamp based on the system.syslog.timestamp. But that new timestamp is 2 hours ahead (something with UTC?). So an event is visible in Kibana 2 hours after it occurred. Kibana settings are default, so date is browser dependend.



Management -> Kibana -> Advanced Settings -> Type tz in the search box if you want to find it quickly. Maybe that helps?

Hi Mario,

Thanks for your answer.

But this doesn’t help, my settings are default, so this one has already ‘browser’.