I've noticed that the @timestamp and the timestamp in the message do not match. I'm using Filebeats to push syslog to my ES cluster.
Here's a screenshot of what I'm talking about. I'm currently using the index template what ships with Filebeat. How do I get the @timestamp and the timestamp from the syslog to match?