I have a question about the timezone showed on Graylog UI for timestamp fields that are not the original “timestamp” field of the event.
For example, I configured admin user to show the timestamp on GMT-3 timezone, with root_timezone = America/Argentina/Buenos_Aires on server.conf, because I live at Buenos Aires.
After that, I have te correct three timezones showed on System/Overview of Graylog UI:
User admin : 2019-11-11 16:54:52 -03:00
Your web browser: 2019-11-11 16:54:52 -03:00
Graylog server: 2019-11-11 16:54:52 -03:00
- The field timestamp show correctly, in GMT-3 timezone
- The agentReceiptTime and deviceReceiptTime fields, obtained from a CEF Input, show the date in Zulu (GMT). Both fields are indexed as “date” type in ElasticSearch.
- The agentTimeZone and the deviceTimeZone fields are America/Argentina/Buenos_Aires
I tried to “play” with timezone setting in CEF Input, for example using “Etc/UTC”, with no luck.
Is there a way to show all the timestamp fields in Graylog UI in the selected timezone (for me America/Argentina/Buenos_Aires), or the only way is an Extractor at Input, or a Decorator at Search (or maybe a Pipeline)?
Thanks in advance.