As you can see in the screenshot, the recording time of the event on the mail server differs from the recording time in the elastic itself by 7 seconds
What could this be related to?
All VMs are on the same network in the same VLAN on the same host in VMware
I would recommend you to parse the events using a pipeline (either logstash or elasticsearch) and use the date filter/processor to set the @timestamp to the one in the log record.
This will make sure the records are displayed in the correct time moment.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.