# Why is the logstash time difference of 5 minutes and 43 seconds before January 1, 1901？

**URL:** <https://discuss.elastic.co/t/why-is-the-logstash-time-difference-of-5-minutes-and-43-seconds-before-january-1-1901/270439>\
**Category:** Logstash\
**Created:** [April 17, 2021, 6:39am UTC](https://discuss.elastic.co/t/why-is-the-logstash-time-difference-of-5-minutes-and-43-seconds-before-january-1-1901/270439 "2021-04-17T06:39:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fei1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fei1/32/87225_2.png) [@Fei1](https://discuss.elastic.co/u/Fei1)\
**Post date:** [April 17, 2021, 6:39am UTC](https://discuss.elastic.co/t/why-is-the-logstash-time-difference-of-5-minutes-and-43-seconds-before-january-1-1901/270439/1 "2021-04-17T06:39:27Z")

</div>

Hello everyone, I am an ELK beginner,

Background:

```auto
Area: GMT+ 8 Time Zone
Linux: CentOS Linux release 8.1.1911 (Core)
Database：mysql Ver 15.1 Distrib 10.3.27-MariaDB, for Linux (x86_64) using readline 5.1
logstash && elasticsearch: 7.12.0

```

When I use logstash to extract data from the mysql database, I found that if the date content is greater than 1901-01-01, the corresponding time will be 8 hours apart, which is correct！  
Sample picture:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a92f3739e7670999387794927a8228beeeb47690.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5fc13093630597358b1d88bd45fe33cb1094ea28.png)

But when the date content of the mysql database is less than 1901-01-01, such as 1900-12-31, the returned time is 1900-12-30T15:54:17.000Z, which is 8 hours, 5 minutes and 43 seconds apart. Is this my mistake?  
Sample picture:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7ea109cd8c65d9ec272967ffd0d327721ce93e9d.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/6/b658794faf94ab4c64441f882fedd5a689d6df13.png)

logstash.conf：

```auto
    input {
      jdbc {
        jdbc_driver_library => "/usr/src/mysql-connector-java-8.0.23/mysql-connector-java-8.0.23.jar"
        jdbc_driver_class => "com.mysql.jdbc.Driver"
        jdbc_connection_string => "jdbc:mysql://localhost:3306/nba"
        jdbc_user => "root"
        jdbc_password => "root"
        jdbc_paging_enabled => true
        jdbc_page_size => "50"
        tracking_column => "unix_ts_in_secs"
        use_column_value => true
        tracking_column_type => "numeric"
        schedule => "*/15 * * * * *"
        statement => "SELECT *, UNIX_TIMESTAMP(update_time) AS unix_ts_in_secs FROM nba_test WHERE (UNIX_TIMESTAMP(update_time) > :sql_last_value AND update_time < NOW()) ORDER BY update_time ASC"
      }
    }
    filter {
      mutate {
        copy => { "number" => "[@metadata][_id]"}
        remove_field => ["unix_ts_in_secs"]
      }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2021, 6:39am UTC](https://discuss.elastic.co/t/why-is-the-logstash-time-difference-of-5-minutes-and-43-seconds-before-january-1-1901/270439/2 "2021-05-15T06:39:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
