# Timestamp explanation

**URL:** <https://discuss.elastic.co/t/timestamp-explanation/214749>\
**Category:** Logstash\
**Created:** [January 13, 2020, 1:53am UTC](https://discuss.elastic.co/t/timestamp-explanation/214749 "2020-01-13T01:53:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![amhulli](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@amhulli](https://discuss.elastic.co/u/amhulli)\
**Post date:** [January 13, 2020, 1:53am UTC](https://discuss.elastic.co/t/timestamp-explanation/214749/1 "2020-01-13T01:53:58Z")

</div>

Hi all,

I'm using ELK 7.4.2  
I have an issue where Kibana throws up an error when I click on any of the bars on the graph in the discover tab (it complains about:

Request to Elasticsearch failed: {"error":{"root\_cause":[{"type":"parse\_exception","reason":"failed to parse date field [-813227399999] with format [epoch\_millis]: [failed to parse date field [-813227399999] with format [epoch\_millis]]"},  
(_ **many of these messages are displayed in the popup - presumably once for each message from the search** _)

I can fix it by changing the "advanced settings =\> timezone for date formatting" from "browser" to "GMT" but I don't want all my dates to be in GMT. I want the display to be in my local timezone as per the timestamp on all of the logs that filebeat-logstash-elasticsearch is ingesting.

What am I doing wrong here?  
regards,  
Andrew.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 13, 2020, 12:56pm UTC](https://discuss.elastic.co/t/timestamp-explanation/214749/2 "2020-01-13T12:56:08Z")

</div>

> [@amhulli](#):
>
> What am I doing wrong here?

Asking in the logstash forum when kibana logs an elasticsearch error.

---

<div class="post-metadata">

**Author:** ![amhulli](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@amhulli](https://discuss.elastic.co/u/amhulli)\
**Post date:** [January 13, 2020, 10:07pm UTC](https://discuss.elastic.co/t/timestamp-explanation/214749/3 "2020-01-13T22:07:23Z")

</div>

@badger thanks for the heads up, but that it appears to me that logstash or filebeat is adding a GMT timestamp before the data is pushed to elasticsearch despite my syslogs having a local timestamp. Hence my tagging as logstash. Apologies if this is still incorrect. I've only been at this for a couple of months.

Ouput of curl [http://localhost:9200/logstash-2020.01.13-000035/\_search?pretty](http://localhost:9200/logstash-2020.01.13-000035/_search?pretty)  
{  
"\_index" : "logstash-2020.01.13-000035",  
"\_type" : "\_doc",  
"\_id" : "jmY3nG8Bx3\_pbs7\_1Wq4",  
"\_score" : 1.0,  
"\_source" : {  
"agent" : {  
"ephemeral\_id" : "925f5e46-14dc-4dc1-93ff-a8c49ae04405",  
"hostname" : "",  
"version" : "7.4.2",  
"id" : "03f53367-f3f7-482a-a69b-fae2771451a5",  
"type" : "filebeat"  
},  
"@timestamp" : " **2020-01-13T00:04:54.000Z**",  
"log" : {  
"offset" : 4965718,  
"file" : {  
"path" : "/data/remotelogs/rsyslog/2020-01-13/.log"  
}  
},  
"tags" : [  
"\_unfiltered"  
],  
"syslog\_severity\_code" : 5,  
"ecs" : {  
"version" : "1.1.0"  
},  
"syslog\_facility" : "user-level",  
"syslog\_severity" : "notice",  
"syslog\_message" : "at 9:34:53 AM",  
"@version" : "1",  
"syslog\_timestamp" : "2020-01-13T09:34:54+09:30",  
"syslog\_hostname" : "",  
"input" : {  
"type" : "log"  
},  
"syslog\_program" : "",  
"syslog\_facility\_code" : 1  
}  
},  
**note: some fields redacted from output above (hostnames etc).**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2020, 10:07pm UTC](https://discuss.elastic.co/t/timestamp-explanation/214749/4 "2020-02-10T22:07:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
