I store syslog into elasticsearch and overview data on Kibana.
I found that the date of @timestamp and _index doesn't match.
The _index is default logstash-* and it seems would automatically adjust from @timestamp.
my doubt is that whether the _index is using UTC, and how to solve it.
this one looks doesn't match:
following data is match:
thank you in advance : )