# Timezone issue with logstash date filter plugin

**URL:** <https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026>\
**Category:** Logstash\
**Created:** [May 30, 2020, 5:15pm UTC](https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026 "2020-05-30T17:15:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [May 30, 2020, 5:15pm UTC](https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026/1 "2020-05-30T17:15:33Z")

</div>

Hi All,

We are ingesting data into elasticsearch using logstash, our problem here is with the timezone issue. We are having a total of 8 date fields in the documents  
for example we are ingesting servicenow data, which will have the fields like createdDate, updatedDate, closedDate, resolvedDate, we have written a mapping for date conversion in kibana which is working fine.

But the problem is the timezone, by default elasticsearch is storing in UTC and my source time zone is in "America/New\_York" the data which is shown in kibana and my source has a difference of 4 hours(basically kibana time is 4 hours ahead of my source data)

with this difference i cant build a trendline which will be of no use it its not proper.

Any advice on this

Thanks  
Gautham

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 30, 2020, 5:50pm UTC](https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026/2 "2020-05-30T17:50:15Z")

</div>

elasticsearch always stores times as UTC. By default kibana will display times in the browser's timezone. You can use the timezone option on a date filter to tell the filter which timezone the logs are in, so that it can set the date in the event to UTC.

Do you have a problem with any of those?

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [May 30, 2020, 6:06pm UTC](https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026/3 "2020-05-30T18:06:42Z")

</div>

@Badger The date filter in logstash is not working...

Below is my time filter

```
filter {
  date { match => ["[result][sys_created_on]", "MM-dd-yyyy HH:mm:ss"]
          timezone => ["America/New_York"] }

```

Thanks  
Gautham

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 30, 2020, 7:12pm UTC](https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026/4 "2020-05-30T19:12:30Z")

</div>

If you want [result][sys\_created\_on] modified then set the target option on the date filter. By default the filter overwrites @timestamp

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2020, 7:12pm UTC](https://discuss.elastic.co/t/timezone-issue-with-logstash-date-filter-plugin/235026/5 "2020-06-27T19:12:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
