# Timestamp Issue - Different Timestamps

**URL:** <https://community.graylog.org/t/timestamp-issue-different-timestamps/8041>\
**Category:** Graylog Central (peer support)\
**Created:** [December 14, 2018, 10:13pm UTC](https://community.graylog.org/t/timestamp-issue-different-timestamps/8041 "2018-12-14T22:13:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AaronFaby](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/aaronfaby/32/47_2.png) [@AaronFaby](https://community.graylog.org/u/AaronFaby)\
**Post date:** [December 14, 2018, 10:13pm UTC](https://community.graylog.org/t/timestamp-issue-different-timestamps/8041/1 "2018-12-14T22:13:05Z")

</div>

Hi all,

We have a Fortinet firewall sending logs to a Graylog server. There was an issue with the timestamps being off, so we followed the advice of this post to create a pipeline to set the desired time zone.

> [@Fortinet, syslog timestamp timezone set wrong](https://community.graylog.org/t/fortinet-syslog-timestamp-timezone-set-wrong/3472):
>
> Hi, i send syslog message from Fortigate 60D and the timestamp provided in the syslog message is in system’s local time (GMT +1) it means 12:00 ( 11:00 Z). Graylog interprets it as UTC which leads to the following issue: on this picture the timestamp is set to 16:18:47.000Z, but this time is send to graylog in GMT +1 time and graylog interpret it as UTC and there is the issue if i need log from 17:18:47 i must waiting to 18:18:47. Is there any options how to solve ? because my other logs are i…

The pipeline seems to work and the timestamp field is set correctly. However, in the Search page when you see the messages from the firewall in the search results box there is the Timestamp field on the far left that shows the current time minus 8 hours. If you mouse over the Timestamp is shows the correct time (+ 8 hours).

Any idea why this is happening? The actual timestamp field also shows the correct time.

Thanks!

---

<div class="post-metadata">

**Author:** ![benvanstaveren](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/benvanstaveren/32/3398_2.png) [@benvanstaveren](https://community.graylog.org/u/benvanstaveren)\
**Post date:** [December 15, 2018, 11:17am UTC](https://community.graylog.org/t/timestamp-issue-different-timestamps/8041/2 "2018-12-15T11:17:44Z")

</div>

I think the timestamp as you see it (and the hover one) are based on the actual value of the timestamp, and the value of the timestamp adjusted via your profile timezone settings, not sure, I’m just guessing here 🙂

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 15, 2018, 11:36am UTC](https://community.graylog.org/t/timestamp-issue-different-timestamps/8041/3 "2018-12-15T11:36:04Z")

</div>

> The pipeline seems to work and the timestamp field is set correctly. However, in the Search page when you see the messages from the firewall in the search results box there is the Timestamp field on the far left that shows the current time minus 8 hours. If you mouse over the Timestamp is shows the correct time (+ 8 hours).

then you do the timestamp conversion wrong.

Graylog will save timestamps always in UTC and in the overview of messages that UTC value is converted to the Timestamp/zone the user has configured in his profile.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 29, 2018, 11:36am UTC](https://community.graylog.org/t/timestamp-issue-different-timestamps/8041/4 "2018-12-29T11:36:06Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
