# Logs have time travelled into the future

**URL:** <https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [June 26, 2020, 2:12pm UTC](https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095 "2020-06-26T14:12:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Magneton](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/magneton/32/1609_2.png) [@Magneton](https://community.graylog.org/u/Magneton)\
**Post date:** [June 26, 2020, 2:12pm UTC](https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095/1 "2020-06-26T14:12:33Z")

</div>

Dear All,

I have a Palo Alto firewall log source using the plugin in the integration package on Graylog 3.1.2.

The log source has an ntp time source set to JST, however logs from the log source are in the future by nine hours therefore the relative search is broken and you can only use the absolute search with the time settings set to nine hours ahead.

No other log sources are suffering the same issue. I have also tried with both the admin user and another user set to JST and the issue still exists with the source.

Am I correct that the log source is most likely the problem i.e log source is taking JST NTP time and further advancing again by nine hours?Anyone here encountered this before?

Cheers

Jake Smith

---

<div class="post-metadata">

**Author:** ![ttsandrew](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@ttsandrew](https://community.graylog.org/u/ttsandrew)\
**Post date:** [June 30, 2020, 8:35pm UTC](https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095/2 "2020-06-30T20:35:35Z")

</div>

Hello @Magneton!

I have encountered a similar issue. In our case the source said that it was sending the timezone but Graylog clearly showed in the message that it was not receiving an offset. I corrected it with a pipeline to shift messages from that source into the correct timezone.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [July 1, 2020, 8:29am UTC](https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095/3 "2020-07-01T08:29:01Z")

</div>

Try to extract timestamp to own field and after that fix timezone with pipeline rule:

```auto
rule "pa_fix_timestamp"
when
  has_field("pa_timestamp")
then
    let new_time = parse_date(value: to_string($message.pa_timestamp), pattern:"yyyy-MM-dd HH:mm:ss", timezone:"Europe/Bratislava");
    set_field("timestamp", new_time);
end

```

You your own pattern for time and date…  
[https://docs.graylog.org/en/3.3/pages/pipelines/functions.html#parse-date](https://docs.graylog.org/en/3.3/pages/pipelines/functions.html#parse-date)

---

<div class="post-metadata">

**Author:** ![Magneton](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/magneton/32/1609_2.png) [@Magneton](https://community.graylog.org/u/Magneton)\
**Post date:** [July 1, 2020, 1:32pm UTC](https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095/4 "2020-07-01T13:32:38Z")

</div>

Thanks all,

That is what I did and move them back to correct issue.

Cheers

Jake

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 15, 2020, 1:32pm UTC](https://community.graylog.org/t/logs-have-time-travelled-into-the-future/16095/5 "2020-07-15T13:32:41Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
