# Winlogbeat timestamp different with event create time

**URL:** <https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 8, 2021, 9:28am UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160 "2021-07-08T09:28:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jacky1](https://avatars.discourse-cdn.com/v4/letter/j/a88e4f/32.png) [@Jacky1](https://discuss.elastic.co/u/Jacky1)\
**Post date:** [July 8, 2021, 9:28am UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160/1 "2021-07-08T09:28:45Z")

</div>

Dears

I got a very strange problem. We installed winlogbeat v7.2 and directly shipped windows event log to ES, configurations about winlogbeat as below:

- name: Security  
ignore\_older: 24h
- name: Microsoft-Windows-NTLM/Operational  
ignore\_older: 24h

```
The logs shipped to ES but for Winlogbeat security channel ,the @timestamp was before the actually event create time ,however the @timestamp of Microsoft-Windows-NTLM/Operational was correct.
 Outputs from ES as below:
 1.for security channel:

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8d0714b60edf042dd6946daa59d06aa72614a0a.png)  
2.for NTLM channel:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/7/17036c22f0e0ac2c1710423770a214cb21f08102.png)

```
Can someone else help me . This issue make me crazy....
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 8, 2021, 11:37am UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160/2 "2021-07-08T11:37:09Z")

</div>

`@timestamp` is the original event log timestamp. event.created is when Winlogbeat generated the document it sends to Elasticsearch.

Elastic Common Schema (ECS) [describes](https://www.elastic.co/guide/en/ecs/current/ecs-event.html) the relationship between the timestamps (`event.ingested` isn't populated out-of-the-box by Winlogbeat.)

> In normal conditions, assuming no tampering, the timestamps should chronologically look like this: `@timestamp` \< `event.created` \< `event.ingested` .

---

<div class="post-metadata">

**Author:** ![Jacky1](https://avatars.discourse-cdn.com/v4/letter/j/a88e4f/32.png) [@Jacky1](https://discuss.elastic.co/u/Jacky1)\
**Post date:** [July 9, 2021, 3:38am UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160/3 "2021-07-09T03:38:46Z")

</div>

Thanks, Andrew  
After investigating the originally events on windows server , seems the winlogbeat agent can't handle the events timely.  
May i know how to speed up the winlogbeat handling performance in order to decrease the time difference.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2021, 5:39am UTC](https://discuss.elastic.co/t/winlogbeat-timestamp-different-with-event-create-time/278160/4 "2021-08-06T05:39:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
