Graylog - Sidecar question

Not that I Know of. Elasticsearch stores all “time” fields in UTC/Epoch. I would double check your times/Date on each device and to make sure there not a problem.

TimeStamp 2021-09-17 08:27;05.496
@timestamp 2021-09-17T07:27:04.088Z
Event_Timestamp 2021/09/17/ 08:26:54

You have something crazy going on, not sure what.

Maybe some of these post will help

https://community.graylog.org/search?q=Timestamp

EDIT: I read over this post trying to figure out an awswer for you about the hour difference.
Just realize something. If Elasticsearch stores all “time” fields in UTC/Epoch ‎and UTC · ‎Greenwich Mean Time (GMT) . Then your statement was

There is your hour difference. I’m not 100% sure but a pipeline might be in your future to set these timestamps correct.