# Timezone in Ingest Pipeline

**URL:** <https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592>\
**Category:** Kibana\
**Tags:** ingest-pipeline\
**Created:** [February 27, 2023, 1:31pm UTC](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592 "2023-02-27T13:31:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fbaer](https://avatars.discourse-cdn.com/v4/letter/f/34f0e0/32.png) [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Post date:** [February 27, 2023, 1:31pm UTC](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592/1 "2023-02-27T13:31:58Z")

</div>

I'm using a IngestPipeline to extract fields from my logs.  
I start with extracting the Timestamp and targeting it into @timestamp s.b.  
now i'm mostly not provided with any timezone from my log and @Timestamp is using its default UTC. This would be fine if i would be in that timezone. But since this will not be only running in one timezone i would like to set the 'timezone' field to something that let it use the local system time. Is there a value like this? Or any other way to achieve this?  
I didn't find anything

```auto
  #Set timestamp to value deduced from log message.
  - date:
      if: ctx.event == null || ctx.event.timezone == null
      field: pac.log.timestamp
      target_field: '@timestamp'
      formats:
        - yyyy-MM-dd HH:mm:ss,SSS
      on_failure:
        - append:
            field: error.message
            value: '{{ _ingest.on_failure_message }}'

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 27, 2023, 2:40pm UTC](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592/2 "2023-02-27T14:40:01Z")

</div>

> [@fbaer](#):
>
> But since this will not be only running in one timezone i would like to set the 'timezone' field to something that let it use the local system time. Is there a value like this? Or any other way to achieve this?

Which system are you talking about it here?

The `date` processor will always use the UTC timezone unless you use the `timezone` option to explictily change the timezone from where the date time string was generated.

If you have events from different timezone you will need to send the timezone with the event and use it in the processor or convert the date string to UTC before sending it.

---

<div class="post-metadata">

**Author:** ![fbaer](https://avatars.discourse-cdn.com/v4/letter/f/34f0e0/32.png) [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Post date:** [February 28, 2023, 7:30am UTC](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592/3 "2023-02-28T07:30:16Z")

</div>

Finally found something that does exactly what i want. It's the `add_locale` processor. I put it in my filebeat.yml and for my system it works perfectly fine.  
Thanks for the hint with the `event.timezone`

Kind Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2023, 7:30am UTC](https://discuss.elastic.co/t/timezone-in-ingest-pipeline/326592/4 "2023-03-28T07:30:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
