We have a Fortinet firewall sending logs to a Graylog server. There was an issue with the timestamps being off, so we followed the advice of this post to create a pipeline to set the desired time zone.
The pipeline seems to work and the timestamp field is set correctly. However, in the Search page when you see the messages from the firewall in the search results box there is the Timestamp field on the far left that shows the current time minus 8 hours. If you mouse over the Timestamp is shows the correct time (+ 8 hours).
Any idea why this is happening? The actual timestamp field also shows the correct time.