Hello, I have a filebeat running on the same node as my ELK (single node cluster) and the timestamp shown in discover tab is +4:30 which is same as my timezone.
So the UTC value of the doc is 2020-09-02T11:01:19.000Z, and since your timezone is +4:30 , what is displayed 2020-09-02T15:31:19.000. Since you're setting Kibana to your browser timezone, this is displayed correctly. You can set the value to UTC then same value would be displayed. Is the persisted timestamp right? could you check the time + timezone on the machine that runs filebeat?
Hi, sorry for the late reply. the problem was someone in our team changed firewall rules causing problems for NTP setting in the elk machine.
so not a problem from ELK.
Thx for letting us know! great that you managed to fix it! So the machine thought it was in a different timezone :), hope it didn't mind that it was forced to time travel!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.