We are running into an issue with several of our graylog instances where the search page does not load correctly. It will add about 8 to 14 mins of time ahead of the latest event. When we load the search page and it uses the default search of last 5 mins, it will not show anything because it’s actually looking at the last 5 minutes that are about 12 minutes in the future.
in addition, if we remove the last 5 mins search from configuration and change it to last 15 mins - when clicking the search button at the top it will show nothing found. We have to then click the green magnifying glass within the search page to load the search. Once again it is adding the extra time to the search page
This is happening with several graylog instances and there is nothing in common across all instances.
Most are running 2.2.3 with elasticsearch 2.4.4. Some were running 2.1.1 and upgraded to 2.2.3 and it did not make a difference. We have not upgraded to 2.3 on any instances yet.