# @timestamp in kibana doesn’t match browser time(local time)

**URL:** <https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976>\
**Category:** Kibana\
**Created:** [February 22, 2018, 4:56am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976 "2018-02-22T04:56:32Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 4:56am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/1 "2018-02-22T04:56:33Z")

</div>

Hi everyone, I input netflow data to ES through nprobe(a netflow collector), but I found that the @timestamp doesn't match the browser time. It stays on 2018/1/20  
for example January 20st 2018, 16:46:00.000 .  
I think the @timestamp should match the local time but the it difference to real time about 1 month.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1b6b7024e5e8af20c3f591d3eefdd450a0a7a73.png)  
How can I tune the @timestamp?

thank you in advance!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 7:47am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/2 "2018-02-22T07:47:08Z")

</div>

Where is the @timestamp field in the documents set? What is the date/time of that host? If it is derived based on a field, what is the content of that field? Can you show a full event that has this problem?

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 8:14am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/3 "2018-02-22T08:14:08Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/9/091e89dad59e627f982b55ebe2d07bf7e9a2f80c.jpg)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e45389216f9df4f6adc0214f907dbe237ef0cbaa.png)  
I didn't modify the @timestamp field.  
this is the nprobe command:  
`nprobe -T "%IPV4_SRC_ADDR %L4_SRC_PORT %IPV4_DST_ADDR %L4_DST_PORT %PROTOCOL %IN_BYTES %OUT_BYTES %FIRST_SWITCHED %LAST_SWITCHED %IN_PKTS %OUT_PKTS %IP_PROTOCOL_VERSION %APPLICATION_ID %L7_PROTO_NAME %ICMP_TYPE %SRC_IP_COUNTRY %DST_IP_COUNTRY %APPL_LATENCY_MS" --redis localhost --collector-port 5556 --elastic "nProbe;nprobe;http://164.14.124.14:9200/_bulk" -b2 -V 9 -i none -n none --json-labels -t 60`  
and the netflow data would be stored in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 8:34am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/4 "2018-02-22T08:34:59Z")

</div>

What does your Logstash config look like? Also, can you please copy and paste a full event in JSON form, rather than providing a screenshot of a partial event?

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 9:40am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/5 "2018-02-22T09:40:05Z")

</div>

I didn't use the logstash. I only input netflow data to ES through nprobe.  
this is my complete doc:

```
{
  "_index": "nprobe",
  "_type": "nProbe",
  "_id": "AWG79tQxbibg1pFGtH5I",
  "_version": 1,
  "_score": null,
  "_source": {
    "IPV4_SRC_ADDR": "61.221.181.46",
    "L4_SRC_PORT": 80,
    "IPV4_DST_ADDR": "163.19.179.175",
    "L4_DST_PORT": 35767,
    "PROTOCOL": 6,
    "IN_BYTES": 42,
    "OUT_BYTES": 0,
    "FIRST_SWITCHED": 1516503810,
    "LAST_SWITCHED": 1516503810,
    "IN_PKTS": 1,
    "OUT_PKTS": 0,
    "IP_PROTOCOL_VERSION": 4,
    "APPLICATION_ID": "0",
    "L7_PROTO_NAME": "HTTP",
    "ICMP_TYPE": 0,
    "SRC_IP_COUNTRY": "",
    "DST_IP_COUNTRY": "",
    "APPL_LATENCY_MS": 0,
    "@version": "1",
    "@timestamp": "2018-01-22T05:22:51.000Z",
    "NPROBE_IPV4_ADDRESS": "163.19.163.230"
  },
  "fields": {
  "@timestamp": [
      1516598571000
    ]
  },
  "sort": [
    1516598571000
  ]
}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 9:45am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/6 "2018-02-22T09:45:08Z")

</div>

If you are not using Logstash, it sounds like nprobe might be setting the `@timestamp` field incorrectly.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 11:17am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/7 "2018-02-22T11:17:16Z")

</div>

Does ES has default \_timestamp?  
Or I can't tune the @timestamp anymore?

thank you !

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 11:26am UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/8 "2018-02-22T11:26:20Z")

</div>

Elasticsearch does not assign any default timestamp, so I suspect it comes from the source. You can process documents in Elasticsearch using an [ingest node pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html), and you should be able to [assign the timestamp the document is indexed into Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/accessing-data-in-pipelines.html#accessing-ingest-metadata) if you feel this would be more appropriate than the data coming from probe. If data is delayed coming into Elasticsearch this would however be misleading.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 3:03pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/9 "2018-02-22T15:03:03Z")

</div>

ok. I got it!

could you teach me how to implement the pipeline setting?  
this is the command:

```
PUT _ingest/pipeline/timestamp 
{
    "description" : "describe pipeline",
    "processors" : [{
                      "set" : {
                                "field": "timestamp",
                                "value": "{{_ingest.timestamp}}"
                              }
                    }]
               }

```

but there are still no \_ingest.timestamp in my doc.

thank you in advance!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 3:05pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/10 "2018-02-22T15:05:27Z")

</div>

Your client application would need to be changed to specify the pipeline when indexing the document, so it may not work.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 3:10pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/11 "2018-02-22T15:10:47Z")

</div>

could you give me an example.

thank you 😀

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 3:17pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/12 "2018-02-22T15:17:54Z")

</div>

Have a look in the docs I linked to earlier.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 3:52pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/13 "2018-02-22T15:52:09Z")

</div>

I refer the doc you mentioned earlier.  
I want to update all data(about 10 thousands data) or let the comming data has the timestamp field.  
this is my command:

```
 PUT _ingest/pipeline/timestamp 
{
    "description" : "describe pipeline",
    "processors" : [{
                      "set" : {
                                "field": "timestamp",
                                "value": "{{_ingest.timestamp}}"
                              }
                    }]
 }

PUT logstash-2018.02.22/_doc/my-id?pipeline=my_pipeline_id
{
  "foo": "bar"
}

```

I am not sure how to use the command here.  
Because I want all the data has the timestamp field.  
so my concept is like this:  
`PUT logstash-*/*/*?pipeline=timestamp`  
but it apparently can't work.  
thank you 🙂

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 3:54pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/14 "2018-02-22T15:54:30Z")

</div>

For this to work, the application indexing into Elasticsearch would need to indicate which pipeline to use as per the example, which I naturally may not be possible. Sorry for not considering that in the first place.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [February 22, 2018, 4:08pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/15 "2018-02-22T16:08:41Z")

</div>

your "per the example" mean a doc = a command ?  
so it's impossible?  
if I have 10 thousands data then I have to query the command 10 thousands times?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2018, 4:20pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/16 "2018-02-22T16:20:42Z")

</div>

It needs to be specified when the document is indexed, which is why it probably will not work. I think the best way is to fix this where the timestamp is generated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 4:20pm UTC](https://discuss.elastic.co/t/timestamp-in-kibana-doesn-t-match-browser-time-local-time/120976/17 "2018-03-22T16:20:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
