# Logs delayed on time

**URL:** https://community.graylog.org/t/logs-delayed-on-time/9875
**Category:** Graylog Central (peer support)
**Created:** [April 9, 2019, 1:55pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875 "2019-04-09T13:55:27Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![phil95](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@phil95](https://community.graylog.org/u/phil95)
#### Post date: [April 9, 2019, 1:55pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/1 "2019-04-09T13:55:27Z")

</div>

Hello everyone,  
I have a very strange behavior of graylog, i’m located in Paris

Current default time zone: ‘Europe/Paris’  
Local time is now: Tue Apr 9 15:29:15 CEST 2019.  
Universal Time is now: Tue Apr 9 13:29:15 UTC 2019.

![graylogtime](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/5c8d9f75a94d11f42fba81557c5850bca26c3a3a.png)

the logs create now appear in Graylog 2h after…  
How can i fix that ?

![graylog_msg](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a54f248ddb175987ffed508a5233aa188e8dfbf4.png)

If i understand well the messages are considered like being in UTC time ?  
but how can i change that from graylog ?

Thanks in advance

---

<div class="post-metadata">

### Author: ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)
#### Post date: [April 9, 2019, 2:12pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/2 "2019-04-09T14:12:35Z")

</div>

What is the time zone on the sending device?

---

<div class="post-metadata">

### Author: ![phil95](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@phil95](https://community.graylog.org/u/phil95)
#### Post date: [April 9, 2019, 2:14pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/3 "2019-04-09T14:14:58Z")

</div>

![fortymanagetime](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/cf0f30ebe043d844ab0a74826ab613dc806ef87f.png)

It’s also Paris time

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [April 9, 2019, 2:30pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/4 "2019-04-09T14:30:32Z")

</div>

does the logfile contain a timestamp information?

If not Graylog assume that the ingested time is UTC … .

---

<div class="post-metadata">

### Author: ![phil95](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@phil95](https://community.graylog.org/u/phil95)
#### Post date: [April 9, 2019, 2:34pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/5 "2019-04-09T14:34:53Z")

</div>

Yeah the log file doesnt not contains timestamp info ☹

> date=2019-04-09 time=14:32:11 devname=4f-net-B devid=7008965 logid=0000000013 type=traffic subtype=forward level=notice vd=interne srcip=192.168.10.26 srcport=51460 srcintf=“interco-fw-int” dstip=10.4.33.25 dstport=8443 dstintf=“interco-infra” poluuid=a-c7cc24e7ecd1 sessionid=481086 proto=6 action=close policyid=278 policytype=policy dstcountry=“Reserved” srccountry=“Reserved” trandisp=noop service=“SVC-TCP-8443” duration=10 sentbyte=525 rcvdbyte=132 sentpkt=6 rcvdpkt=3 appcat=“unscanned” devtype=“Fortinet Device” mastersrcmac=00:09:0f:09:27:04 srcmac=00:09:0f:09:27:04

Is it possible simply with the extractors to add 2h on the UTC timestamp create by graylog ?

---

<div class="post-metadata">

### Author: ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)
#### Post date: [April 9, 2019, 3:21pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/6 "2019-04-09T15:21:21Z")

</div>

with the processing pipelines you can do that. Like mentioned here:

> [@Pipeline parsing and setting correct timestamp](https://community.graylog.org/t/pipeline-parsing-and-setting-correct-timestamp/914):
>
> Hello, I like to parse and set the correct timestamp to logmessages with the pipeline feature. I have all ready fields with hour,minutes,seconds, day of month and so on… My first pipeline stage is detecting the logs (for example application server type a). The second stage is parsing the logmessage with the proper grok pattern. Now I have the issue, that the logmessage timestamp and the graylog (elasticsearch) timestamp differ a view seconds. My idea is to use the parsed fields from stage two…

Other postings in the community will guide you!

---

<div class="post-metadata">

### Author: ![phil95](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@phil95](https://community.graylog.org/u/phil95)
#### Post date: [April 9, 2019, 3:33pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/7 "2019-04-09T15:33:07Z")

</div>

I’m searching since a while and i just found out this post that resolved my issue 😃 😃

> [@Fortigate graylog modifies timestamp?](https://community.graylog.org/t/fortigate-graylog-modifies-timestamp/5757/7):
>
> Timestamp is still +2 and timestamp in the logmessage still has Z behind it. [afbeelding] Using this now: rule “fortigate timestamp” when has\_field(“devname”) && has\_field(“date”) && has\_field(“time”) then let build\_message\_0 = concat(to\_string($message.date), " "); let build\_message\_1 = concat(build\_message\_0, to\_string($message.time)); let new\_timestamp = parse\_date(value:to\_string(build\_message\_1), pattern:“yyyy-MM-dd HH:mm:sss”, timezone:“Europ/Amstedam”); set\_field(“timestamp”, ne…

Thanks a lot !!!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)
#### Post date: [April 23, 2019, 3:41pm UTC](https://community.graylog.org/t/logs-delayed-on-time/9875/8 "2019-04-23T15:41:00Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
