# Graylog exctractor specify timezone other than UTC

**URL:** <https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663>\
**Category:** Graylog Central (peer support)\
**Created:** [December 30, 2017, 9:40pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663 "2017-12-30T21:40:44Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [December 30, 2017, 9:40pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/1 "2017-12-30T21:40:44Z")

</div>

Hello team!

I have a message with timestamp without specified timezone in it, but timezone actually -6 CST. It is not UTC.

Message:  
“2017/12/30 15:19:57 [error] 27739#0: \*3722503 limiting requests, excess: 0.062 by zone “wp-login”, client: 10.189.252.6, server: [blog.com](http://blog.com), request: “POST /ame/wp-login.php HTTP/1.1”, host: “[www.ame.com](http://www.ame.com)””

With following GROK pattern:  
%{DATESTAMP\_EVENTLOG:timestamp;date;yyyy/MM/dd HH:mm:ss}

Is there a way to specify at time parsing tell that timestamp in message should be stored as -6 CST timestamp, not UTC. Because i see:

timestamp  
Sat Dec 30 15:19:57 UTC 2017

But it is actually not UTC timezone, but CST -6.

---

<div class="post-metadata">

**Author:** ![bubba198](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/bubba198/32/803_2.png) [@bubba198](https://community.graylog.org/u/bubba198)\
**Post date:** [December 31, 2017, 2:07am UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/2 "2017-12-31T02:07:18Z")

</div>

there’s an option in the graylog script graylog-ctl which comes with the OVA to set the time zone. If you’re not using the OVA one must set the time zone inside the config files but that will require looking at the docs.

graylog-ctl is explaned here:

[http://docs.graylog.org/en/2.3/pages/installation/virtual\_machine\_appliances.html](http://docs.graylog.org/en/2.3/pages/installation/virtual_machine_appliances.html)

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 31, 2017, 4:21pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/3 "2017-12-31T16:21:38Z")

</div>

if you use GROK - it is easy: [http://docs.graylog.org/en/2.4/pages/extractors.html?highlight=grok#using-grok-patterns-to-extract-data](http://docs.graylog.org/en/2.4/pages/extractors.html?highlight=grok#using-grok-patterns-to-extract-data)

%{DATA:timestamp;date;dd/MMM/yyyy:HH:mm:ss **Z** } where Z is the timezone after RFC 822 ([https://docs.oracle.com/javase/7/docs/api/java/text/SimpleDateFormat.html](https://docs.oracle.com/javase/7/docs/api/java/text/SimpleDateFormat.html))

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [December 31, 2017, 5:25pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/4 "2017-12-31T17:25:33Z")

</div>

As i said, i don’t have in log Z, time zone. It is nginx error log format and it can not be changed.

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [December 31, 2017, 5:42pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/5 "2017-12-31T17:42:09Z")

</div>

you can extract the date first as a string (a new field), then use a copy extractor with date converter. Note that the new field must be a string; the date converter does not seem to work from date type to date type. The date converter allows you to specify the time zone.

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [December 31, 2017, 5:54pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/6 "2017-12-31T17:54:40Z")

</div>

Maybe more right way specify default graylog’s timezone in config?

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [December 31, 2017, 11:22pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/7 "2017-12-31T23:22:28Z")

</div>

Already setup in /etc/graylog/server/server.conf:

root\_timezone = America/Chicago

But actually log still parsed in UTC if timezone not specified. Is there a way to specify default timezone? Other than parse as string -\> convert string to date?  
Why config’s root\_timezone do not impact extractor default timezone?

---

<div class="post-metadata">

**Author:** ![bubba198](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/bubba198/32/803_2.png) [@bubba198](https://community.graylog.org/u/bubba198)\
**Post date:** [January 1, 2018, 6:34pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/8 "2018-01-01T18:34:09Z")

</div>

I never thought of doing any kind of date/time conversion on-the-fly at the extractor level; I just let it ride as it wants and then Graylog allows me to search using my time zone ranges (PST in my case) and I get correct hits instead of doing UTC searches. Screenshot… hope I understood the issue correctly.

 ![utc](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/29ae0718dfa2885512dea758f074f10cc7e59b0f.png)

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [January 2, 2018, 8:06am UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/9 "2018-01-02T08:06:38Z")

</div>

Your log message do not have time stamp. So graylog set own timestamp when get this message. In my case log message which come to graylog has own time stamp which set by application (nginx error log) and i want that it will be the same in graylog so i use message extractor on field message:

> %{DATESTAMP\_EVENTLOG:timestamp;date;yyyy/MM/dd HH:mm:ss}

Message:

> 2017/12/30 15:19:57 [error] 27739#0: \*3722503 limiting requests, excess: 0.062 by zone “wp-login”, client: 10.189.252.6

And in message time in CST (-5) but it is not specified in log and when it parsed by Graylog he has no idea which timezone use and consider it as log in UTC format, but it actually CST.

The best decision here is change log format in application that add timezone after time, but it impossible as nginx do not permit change format of error log. So i need anyway tell Graylog that my time not in UTC timezone, default timezone in graylog config file is not impact this, graylog-ctl i no have as this is not OVA installation.

 ![05](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/bbc0b084ccd53e0055148f2f2f44f975a373e761.png)

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [January 2, 2018, 8:21am UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/10 "2018-01-02T08:21:16Z")

</div>

Hej @mpolitaev

you could use the [format-date](http://docs.graylog.org/en/2.4/pages/pipelines/functions.html#format-date) function for example to let Graylog know that this is not UTC …

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [January 2, 2018, 2:30pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/11 "2018-01-02T14:30:24Z")

</div>

Hi jan!  
Happy new year!

Seems format-date can help, i have create pipeline rule with one “Stage 0” attached to “All messages” stream.

I need convert timestamp field but only for those messages which with wrong timezone (UTC) it can be sorted by field “type” = “nginx\_error” is there possible setup rule to find value in fields?

I only found has\_field function will see only whether my field “type” exist. Is there a way filter “type” fields only which has “nginx\_error” value?

Thank you.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [January 3, 2018, 8:35am UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/12 "2018-01-03T08:35:56Z")

</div>

writing a rule is hard without knowing what fields are present - those rules are most uniq.

You could even check if the date contains a timezone or not.

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [January 3, 2018, 10:53am UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/13 "2018-01-03T10:53:24Z")

</div>

For check timezone in date in timestamp field i should look into field value, but which function can do this? I found function “has\_field” but it is check only if field present. Filed “timestamp” present for all messages, i need sort those who has format “dd/MMM/yyyy HH:mm:ss” and not change other like “dd/MMM/yyyy HH:mm:ss Z”

---

<div class="post-metadata">

**Author:** ![jtkarvo](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jtkarvo](https://community.graylog.org/u/jtkarvo)\
**Post date:** [January 3, 2018, 2:19pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/14 "2018-01-03T14:19:22Z")

</div>

I think the easiest way would be making a stream with condition source is equal to the source id, and use the pipeline rule for that. Most log sources will send logs with reasonable timestamps, so this would not be too difficult.

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [January 3, 2018, 2:24pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/15 "2018-01-03T14:24:14Z")

</div>

I also thought about separate stream, but maybe it possible sort logs rely on field value in pipeline only? At all is it possible that pipeline look into field value? Maybe some function? Like has\_field or match\_field\_value?

---

<div class="post-metadata">

**Author:** ![mpolitaev](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mpolitaev/32/729_2.png) [@mpolitaev](https://community.graylog.org/u/mpolitaev)\
**Post date:** [January 4, 2018, 8:53pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/16 "2018-01-04T20:53:05Z")

</div>

The problem was in UTC timezone on Graylog server, i have setup America/Chicago and all timestamps without timezones are parsed in -6 timezone! Great!

Thank for all guys!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 18, 2018, 8:53pm UTC](https://community.graylog.org/t/graylog-exctractor-specify-timezone-other-than-utc/3663/17 "2018-01-18T20:53:21Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
