Timestamp ISSUE

Have you checked the times are the same on the sending system to logstash and then to Elasticsearch. You should also be able to add in Discover the ingest timing.. if there is a delay in ingestion and processing those documents.