I have installed graylog version 2.1.0-beta. Collecting nginx error and access logs in UTC+8. But stream alert triggers in UTC which means after 8 hours. How can I alert stream correct? Is there any other method that change timezone received logs.

Thank you,

you should not install this ancient version of Graylog. Current stable release is 3.0. Your selected release is from August 2016. No security updates or bugfixes for your version.

Graylog will work with the ingested messages as they are UTC if no timezone is give, what is the point in this.

Thank you for reply. I will update graylog latest version. But is there any pipeline rule that replace nginx log timestamp?

such can be found in this community with a little search … or you can build it your own with the given information.

