We have a number of Palo Alto’s forwarding their logs to Graylog. Unfortunately, the timestamps are in EST and Graylog interprets that as UTC. as a result, the log messages appear 4 hour prior. Our network team is not willing to change the timezone on the Palo Altos so I need to have another solution.
I created an extractor using Copy Input on the
timestamp field and have tried both the date convertor and the flexibly parse date convertor to update set the timezone to EST. however, neither of these seemed to work and the timestamp still appears in UTC
Using the current version of Graylog (v2.2.3) 3 node cluster with a 3 node ES cluster in the backend.
Any help would be greatly appreciated.