# Timestamp copy problem with Timezone

**URL:** <https://discuss.elastic.co/t/timestamp-copy-problem-with-timezone/279992>\
**Category:** Logstash\
**Created:** [July 29, 2021, 1:36pm UTC](https://discuss.elastic.co/t/timestamp-copy-problem-with-timezone/279992 "2021-07-29T13:36:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kubix0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kubix0/32/104574_2.png) [@Kubix0](https://discuss.elastic.co/u/Kubix0)\
**Post date:** [July 29, 2021, 1:36pm UTC](https://discuss.elastic.co/t/timestamp-copy-problem-with-timezone/279992/1 "2021-07-29T13:36:52Z")

</div>

Hey there, my first topic here.  
Wanted to ask some help because I can´t find a answer/solution for my problem.

So, I have a Logstash filter that copy the @timestamp filed to make Timestamp more friendly for elastalert.

My logstash filter:  
Input into logstash: @timestamp: 2021-07-29T **12** :00:00.000Z

```auto
filter {
  grok {
    match => { "@timestamp" => "%{GREEDYDATA:logDATE}T%{NOTSPACE:logTIME}\.%{NOTSPACE}" }
  mutate
  {
    add_field => { "elasticalert_timestamp" => "%{logDATE} %{logTIME}" } }
  mutate
  {
    remove_field => ["logDATE", "logTIME"] }
  }
  }

```

Output of elasticalert\_timestamp: 2021-07-29 **12** :00:00  
Kibana view of @timestamp: 2021-07-29T **13** :00:00.000Z

Today, I noticed that @timestamp and elasticalert\_timestamp are 1h behind.

So in Kibana Index View I have it at 13:00 but on @timestamp json view is 12:00.. and I wanted to have the right time in elasticalert\_timestamp (that is 13:00).

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 29, 2021, 3:22pm UTC](https://discuss.elastic.co/t/timestamp-copy-problem-with-timezone/279992/2 "2021-07-29T15:22:33Z")

</div>

Hi,

you have to take in consideration that the timestamp you see on kibana are directly adapted for your point of view through your kibana settings of the timezone.

Logstash and elasticsearch stores time data as UTC.

That's probably why you're seeing 1h behind

---

<div class="post-metadata">

**Author:** ![Kubix0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kubix0/32/104574_2.png) [@Kubix0](https://discuss.elastic.co/u/Kubix0)\
**Post date:** [July 29, 2021, 3:31pm UTC](https://discuss.elastic.co/t/timestamp-copy-problem-with-timezone/279992/3 "2021-07-29T15:31:21Z")

</div>

Hi,  
Yes, I know that Kibana have the ` "event.timezone": ["+01:00"]`  
The question is, how I add +1 so that my field **elasticalert\_timestamp** get the same kibana time using the logstash.

Yes I could use grok in the event.timezone field to get the "1" and use math plugin to add it to elasticalert\_timestamp but wanted to avoid to not spend more resources with this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2021, 8:39am UTC](https://discuss.elastic.co/t/timestamp-copy-problem-with-timezone/279992/5 "2021-09-01T08:39:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
