I am experiencing a strange thing with the date in the syslog log in filebeat. I am using the default ingest node pipeline (logs-system.syslog-0.12.7) which creates a new timestamp based on the system.syslog.timestamp. But that new timestamp is 2 hours ahead (something with UTC?). So an event is visible in Kibana 2 hours after it occurred. Kibana settings are default, so date is browser dependend.
I think I found the answer. When changing the timezone in my Syslog server after the agent is enrolled the old time will appear in the logs.
Unenroll and re-enroll of the agent will solve the problem.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.