# Timestamp issue on storing logs

**URL:** <https://discuss.elastic.co/t/timestamp-issue-on-storing-logs/94972>\
**Category:** Logstash\
**Created:** [July 28, 2017, 2:30pm UTC](https://discuss.elastic.co/t/timestamp-issue-on-storing-logs/94972 "2017-07-28T14:30:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 28, 2017, 2:30pm UTC](https://discuss.elastic.co/t/timestamp-issue-on-storing-logs/94972/1 "2017-07-28T14:30:33Z")

</div>

I don't know why logstash creating timestamp with 1hr lag approx. Initially I thought , problem might be on Elasticsearch.

but after I did some analysis, by just redirect logstash out to stdout file. then I saw "wrong timestamp registered by logstash". I don't know how its logging that timestamp even I haven't mentioned anything in my configuration file to use logs timestamp field.

this is my logstash configuration:

```
input {

  kafka { 
        bootstrap_servers =>["localhost:9092"]
        topics => ["app"]
        codec => "json"
  }
}

filter {
	geoip {
		source => "ip"
	}
}

output {
          elasticsearch {

                    hosts => ["10.11.12.169:9200"]
                    index => "app-%{+YYYY.MM.dd}"
                 }
}

```

Server date:

```
[root@srv1 conf.d]# date
Fri Jul 28 14:27:59 GMT 2017
[root@srv1 conf.d]#

```

logstash stdout log:

> "start\_time": "2017-07-28T13:22:00.049Z",  
> "@timestamp": "2017-07-28T13:22:40.000Z",  
> "flow\_id": "kAD/////AP//CP////8AAAE0kChFRUEnLLre",  
> "last\_time": "2017-07-28T13:22:00.049Z",

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 30, 2017, 1:22pm UTC](https://discuss.elastic.co/t/timestamp-issue-on-storing-logs/94972/2 "2017-07-30T13:22:12Z")

</div>

my source is from packetbeat and push the data into kafka. And Using logstash to feccth logs from Kafka.

I checked the kafka stored message using consumer script. data had a timestamp field with correct value. But logs stored on elasticsearch has different timestamp. So I suspect something wrong with logstash.

yeah, its rights ,timestamp fields is getting changed @logstash side. I don't know why its changing the timestamp field, when server [where logstash is running] is in correct timestamp.

Can someone please help me on this. as my production system entire got affected due to this time mismatch issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2017, 1:22pm UTC](https://discuss.elastic.co/t/timestamp-issue-on-storing-logs/94972/3 "2017-08-27T13:22:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
