# @timestamp always 8h exact more than the matching time?

**URL:** <https://discuss.elastic.co/t/timestamp-always-8h-exact-more-than-the-matching-time/59236>\
**Category:** Logstash\
**Created:** [August 29, 2016, 9:16pm UTC](https://discuss.elastic.co/t/timestamp-always-8h-exact-more-than-the-matching-time/59236 "2016-08-29T21:16:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [August 29, 2016, 9:16pm UTC](https://discuss.elastic.co/t/timestamp-always-8h-exact-more-than-the-matching-time/59236/1 "2016-08-29T21:16:35Z")

</div>

Hi I know there are quite a few topics on this. But still i couldn't figure it out after reviewing them.

THIS is how i date filtered _ **date** _ field to target @timestamp (tried with and without timezone).

date{  
match =\> ["date", "YYYY-MM-dd HH:mm:ss", "ISO8601"]  
timezone =\> "US/Pacific"  
target =\> "@timestamp"  
}

HOWEVER, when I parsed it, @timestamp is exactly 8hours ahead of _date_ field.  
{  
**"@timestamp"** =\> "2016-01-01T07:02:14.000Z",  
"app\_id" =\> "as",  
**"date"** =\> "2015-12-31 23:02:14",  
"member\_id" =\> 25241916,  
"locale" =\> "en\_US",  
"p\_source" =\> "web",  
"p\_typeId" =\> 2,  
"p\_contentId" =\> 98060092  
}

Would you have any ideas of why?

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [August 29, 2016, 9:23pm UTC](https://discuss.elastic.co/t/timestamp-always-8h-exact-more-than-the-matching-time/59236/2 "2016-08-29T21:23:24Z")

</div>

When i change the timezone to Ireland (Europe Dublin), it got right between @timestamp and **date** field. I know that our server is in Ireland, so maybe thats why. **But how can Logstash recognize it**??

Got right when i set timezone to Europe/Dublin  
{  
" **@timestamp**" =\> "2015-12-31T23:02:14.000Z",  
"app\_id" =\> "as",  
" **date**" =\> "2015-12-31 23:02:14",  
"member\_id" =\> 25241916,  
"locale" =\> "en\_US",  
"p\_source" =\> "web",  
"p\_typeId" =\> 2,  
"p\_contentId" =\> 98060092  
}

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [August 29, 2016, 11:48pm UTC](https://discuss.elastic.co/t/timestamp-always-8h-exact-more-than-the-matching-time/59236/3 "2016-08-29T23:48:58Z")

</div>

Got it. Elastic uses UTC by default. And we are suggested not to change it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/timestamp-always-8h-exact-more-than-the-matching-time/59236/4 "2017-07-06T04:41:02Z")

</div>


