I have a stand allone architecture. Logs are sent from syslog_ng server to logstash - > Elasticsearch -> kibana.
I have a probleme with the timestamp as the capture below shows
The logs are received at ELK at 2:11 AM but the timestamp show the logs receveid at 1:48 AM.
Did you have any idea about the solving of this issue?
Have you checked the times are the same on the sending system to logstash and then to Elasticsearch. You should also be able to add in Discover the ingest timing.. if there is a delay in ingestion and processing those documents.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.