# @timestamp field not reflected after resetting server time!

**URL:** <https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179>\
**Category:** Logstash\
**Created:** [July 22, 2016, 12:21pm UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179 "2016-07-22T12:21:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 22, 2016, 12:21pm UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179/1 "2016-07-22T12:21:35Z")

</div>

I'm running both Logstash server and elasticsearch in same machine.

After parsing the logs into ELS , I checked it through kibana where the data shown with 5 minutes delay. Then I found that the server time [NTP] is not configured correctly that was running with 5 minutes delay. that's the reason why I saw the same delay in my kibana.

Strange here is ,after reset my server time with correct one, I couldn't see the data in correct time format. Still it shows with 5 seconds delay. Should I need to reset the time settings somewhere else

Server time:  
[root@ip202 conf.d]# date  
Fri Jul 22 12:11:08 GMT 2016  
[root@ip202 conf.d]#

Logstash Output log:  
"@timestamp" =\> "2016-07-22T12:06:49.161Z",

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2016, 5:37pm UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179/2 "2016-07-22T17:37:58Z")

</div>

Where does `@timestamp` come from? Are you parsing it from a log file's contents or it Logstash populating it by itself with the current time? Please show the output of `date | /opt/logstash/bin/logstash agent`.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 23, 2016, 10:54am UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179/3 "2016-07-23T10:54:31Z")

</div>

I got that `@timestamp` value from logstash.stdout log file and this timestamp value is being populated by logstash itself with current time.

> [root@ip202 ~]# date | /opt/logstash/bin/logstash agent  
> Settings: Default pipeline workers: 2  
> Pipeline main started  
> {  
> "message" =\> "Sat Jul 23 10:52:15 GMT 2016",  
> "@version" =\> "1",  
> "@timestamp" =\> "2016-07-23T10:52:22.747Z",  
> "type" =\> "stdin",  
> "host" =\> "ip202.ip-51-255-232.eu"  
> }  
> Pipeline main has been shutdown  
> stopping pipeline {:id=\>"main"}  
> [root@ip202 ~]#

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 26, 2016, 7:10am UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179/4 "2016-07-26T07:10:43Z")

</div>

@magnusbaeck ,, Explaining my issue bit more clear

I'm using filebeat/logstash-forwarder to push the logs from my remote servers. for now, I've tried to push the logs from 2 remote servers which are running with different OS version.

1.) Centos 6.7 --\> Here I'm using "Filebeat" .  
2.) Centos 5.8 --\> Here I'm using "logstash-forwarder". [As filebeat doesn't support on this version]

I don't have any problem with parsing Centos5.8 server logs through logstash-forwarder. timestamp field is updated/logged properly in elasticsearch.  
But, in CentOS6.7 , As mentioned earlier post , timestamp field has a 5 minutes delay .  
Strange here is, If I stopped the filebeat and installed logstash-forwarder in CentOS6.7 machine, timestamp field updated properly and stored in Elasticsearch and can see the data in kibana without any delay.

I got confused here, Is timestamp field generated by filebeat ?. I though, this field value can be handled by logstash servers.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 28, 2016, 1:24pm UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179/5 "2016-07-28T13:24:46Z")

</div>

I tried again with filbeat. Still hit with same problem. Anyone have idea what is reason for this ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/timestamp-field-not-reflected-after-resetting-server-time/56179/6 "2017-07-06T04:46:08Z")

</div>


