# Timezone related issue

**URL:** <https://discuss.elastic.co/t/timezone-related-issue/308596>\
**Category:** Elasticsearch\
**Created:** [June 30, 2022, 2:49pm UTC](https://discuss.elastic.co/t/timezone-related-issue/308596 "2022-06-30T14:49:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pranjal\_Sett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranjal_sett/32/98834_2.png) [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Post date:** [June 30, 2022, 2:49pm UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/1 "2022-06-30T14:49:48Z")

</div>

Hello Again,

I am getting as actual data for the attribute(FILE\_CREATION\_DATE) as "2022-06-30 16:34:27" but when I see in the kibana table format; I can see the time has been added exactly two hours. Here is the data in kibana Table : FILE\_CREATION\_DATE Jun 30, 2022 @ 18:34:27.000.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc49e6ad7a285cd041e07a39a3af26a4c56226a5.png)

timezone : "Europe/Stockholm"

In index template my custom format for the datetime field is : yyyy-MM-dd HH:mm:ss.

How can I get the actual time in kibana also? Is there anyhow I can mention in the Index template so that it should not added exactly 2 hours.

Regards,  
Pranjal Sett

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [June 30, 2022, 3:37pm UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/2 "2022-06-30T15:37:35Z")

</div>

Hi @Pranjal_Sett

Change timezone here: Kibana \> Management \> Advanced Settings -\> Timezone for date formatting

---

<div class="post-metadata">

**Author:** ![Pranjal\_Sett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranjal_sett/32/98834_2.png) [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Post date:** [July 1, 2022, 5:24am UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/3 "2022-07-01T05:24:23Z")

</div>

Hi @RabBit_BR

Did that change but issue still persists.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 1, 2022, 5:59am UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/4 "2022-07-01T05:59:21Z")

</div>

Hi @Pranjal_Sett

How are you ingesting your data?

Most likely the problem is that you're ingesting this FILE\_CREATION\_DATE `date` field without a time zone and so the default is to assume UTC timezone.

At ingestion time you should provide the time zone for that for that field then I think you'll see what you expect.

A `date` field in elastic is always stored as UTC and then displayed in Kibana in the local time zone (assuming default settings)

---

<div class="post-metadata">

**Author:** ![Pranjal\_Sett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranjal_sett/32/98834_2.png) [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Post date:** [July 1, 2022, 8:22am UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/5 "2022-07-01T08:22:25Z")

</div>

> [@Pranjal\_Sett](#):
>
> yyyy-MM-dd HH:mm:ss

Hi @stephenb ,

In that case I have to write this logic in Logstash like below:

date {  
match =\> ["FILE\_CREATION\_DATE" , "yyyy-MM-dd HH:mm:ss"]  
timezone =\> "Europe/Stockholm"  
}

remove the custom date format for FILE\_CREATION\_DATE from index template then delete the index and restart the logstash .. right?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 1, 2022, 2:19pm UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/6 "2022-07-01T14:19:54Z")

</div>

That sounds about right.

You Could probably update the index template to have the new / correct date format If you wanted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2022, 2:19pm UTC](https://discuss.elastic.co/t/timezone-related-issue/308596/7 "2022-07-29T14:19:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
