Hi. I+m having a problem with my suricata logs on kibana. My server and kibana are configured with the time Europe/Lisbon. The eve.json logs are in the correct timestamp. But when i move to kibana, the logs are shown in a different day with different hours. Like, today is 3/10/2020 and the logs are shown like 1/10/2020.
Are the log in your discovery print and the one of the json the same? I can't see where the error could be.
Can you pick up a log where the date is showing up with different days in both discovery and the source json? Show in discovery all the date fields that your document have, not jus the one used by the kibana index pattern. Also, share the json document using the code feature <\>, it is better to read and to try to reproduce.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.