Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.
Don’t forget to select tags to help index your topic!
1. Describe your incident:
See title. The logs coming into graylog are off by 4 hours even though everything is configured for America/Detroit.
2. Describe your environment:
-
OS Information: Ubuntu 22.04
-
Package Version: Graylog 5.0.7 / Opensearch 2.5 / Mongodb 6.0.6
-
Service logs, configurations, and environment variables:
Graylog/MongoDB server:
timedatectl status
Local time: Tue 2023-05-16 13:42:48 EDT
Universal time: Tue 2023-05-16 17:42:48 UTC
RTC time: Tue 2023-05-16 17:42:48
Time zone: America/Detroit (EDT, -0400)
System clock synchronized: yes
NTP service: active
RTC in local TZ: no
Opensearch server:
timedatectl status
Local time: Tue 2023-05-16 13:43:33 EDT
Universal time: Tue 2023-05-16 17:43:33 UTC
RTC time: Tue 2023-05-16 17:43:33
Time zone: America/Detroit (EDT, -0400)
System clock synchronized: yes
NTP service: active
RTC in local TZ: no
Fortigate:
Logs in Graylog dashbaord:
3. What steps have you already taken to try and solve the problem?
Verified all timed/date configuration. Restarted services and even restarted servers.
4. How can the community help?
Any guidance to get timestamps in graylog web dashboard to match actual log timestamp would be appreciated.
Helpful Posting Tips: Tips for Posting Questions that Get Answers [Hold down CTRL and link on link to open tips documents in a separate tab]