Okay. And what does the complete configuration look like? Does the date filter come after the grok filter or whatever you're using the parse the message field?
Um, wait. What's the timezone on the machine where you're running Logstash? UTC+8, by any chance? It looks like the date filter is working fine. Perhaps you need to set the date filter's timezone option (or have it parse the GMT string in the timestamp) to override the timezone used when parsing the timestamp.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.