# Where does Kibana get the timepicker's "now" value?

**URL:** <https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270>\
**Category:** Kibana\
**Created:** [April 10, 2019, 4:52pm UTC](https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270 "2019-04-10T16:52:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hansell.baran](https://avatars.discourse-cdn.com/v4/letter/h/e9c0ed/32.png) [@hansell.baran](https://discuss.elastic.co/u/hansell.baran)\
**Post date:** [April 10, 2019, 4:52pm UTC](https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270/1 "2019-04-10T16:52:40Z")

</div>

Hello!

I noticed that when I use Kibana's "Quick" timepickers, the most recent data shown is 2 hours behind my browser's time. This only happens with the "Last..." options. If I use "Today", all the data is shown.

It is worth mentioning that the server (Ubuntu 18.04) where Kibana runs has UTC (running date command returns "Wed Apr 10 16:17:15 UTC 2019"). I tried changing the timezone but it does not help.

Where does Kibana get the "now" date?

Some additional details:

I configured Kibana to use UTC instead of the default Browser setting (Kibana -\> Managament -\> Advanced Settings -\> **dateFormat:tz** ) (If I do not use UTC, then log timestamps do not match Kibana timestamps)

From this post,

> [@6.2.0 - Some "Quick time ranges" have been removed](https://discuss.elastic.co/t/6-2-0-some-quick-time-ranges-have-been-removed/119076):
>
> Hi there, I upgraded my dev environnement in version 6.2.0 this morning and observed that some time ranges I used to select in "Quick" section are no longer available. Including "Yesterday" and "Day before yesterday" among many others. Is it intentional ? According to me, those time ranges are necessary for people running daily batches process. Kuaaaly

I got to know that there is a **timepicker:quickRanges** setting that I modified to "make it work" for the "Last 7 days" option. I changed this:  
{  
"from": "now-7d",  
"to": "now",  
"display": "Last 7 days",  
"section": 1  
}  
into this:  
{  
"from": "now-7d",  
"to": "now/d",  
"display": "Last 7 days",  
"section": 1  
}

However, I would like ALL "Last..." options to use the now date that my browser is using which should happen by using "Browser" in the **dateFormat:tz** setting.

How should I fix this issue?

Here are some screen shots to visualize the problem:

Kibana with **dateFormat:tz** = UTC and default "Quick" timepicker options:

 ![41](https://us1.discourse-cdn.com/elastic/original/3X/2/4/247db72d683ae26dbcfe2eafe851731b88ae4d6c.png)

Kibana with **dateFormat:tz** = Browser and default "Quick" timepicker options:

 ![49](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a68c829241d7904f1b6f69f814960996cb9951e.png)

Kibana with **dateFormat:tz** = UTC and modified "Quick -\> Last 7 days" timepicker option (notice that more data is visualized as the "to" property is set to "now/d"):

 ![38](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a277027ab176fcb080495eee4aab239a17a00b3.png)

Any help would be greatly appreciated! Thanks!

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 12, 2019, 3:31pm UTC](https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270/2 "2019-04-12T15:31:17Z")

</div>

Can you check the request in the inspector (top right) for all these options and see if what the actual UNIX timestamps are used for the request and filters?

---

<div class="post-metadata">

**Author:** ![hansell.baran](https://avatars.discourse-cdn.com/v4/letter/h/e9c0ed/32.png) [@hansell.baran](https://discuss.elastic.co/u/hansell.baran)\
**Post date:** [April 17, 2019, 8:47am UTC](https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270/3 "2019-04-17T08:47:09Z")

</div>

Thanks for your response @Marius_Dragomir...

I believe the "now" is from perhaps calling Javascript "Date.now()" or something similar (I did not look into the source code). However, I solved the issue by modifying the Elasticsearch pipelines.

Since there is no detailed documentation regarding the Filebeat modules and how their pipelines are structured and how they work, i.e., how they parse dates (timezones specifically), and I am not an ELK expert, I assumed that the parsed timestamp "would be accurrate" (consider the timezone if there is one), however, since all the logs in my server have timezone GMT+2, I didn't realise that the Filebeat Nginx module was parsing the logs considering they were GMT+0.

I modified ALL the Elasticsearch pipelines (specifically those related to the filebeat / nginx modules), so that the "date" processor would have an extra property "timezone:" "CEST", reverted Kibana to "Browser" and now logs are showing up with the correct timestamp and the "Quick" "Last x..." options work as expected! Awesome!

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 19, 2019, 10:22am UTC](https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270/4 "2019-04-19T10:22:58Z")

</div>

Ah yes, Elasticsearch by default will assume UTC unless you specify a timezone.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2019, 10:23am UTC](https://discuss.elastic.co/t/where-does-kibana-get-the-timepickers-now-value/176270/5 "2019-05-17T10:23:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
