Currently scratching my head over timezone issue.
I have all timezones for all servers unified as “Europe/London”.
System/Overview/Time configuration shows correct time:
User admin :2020-08-25 17:22:34 +01:00
Your web browser:2020-08-25 17:22:34 +01:00
Graylog server:2020-08-25 17:22:34 +01:00
Additionally, the messages I am sending into Graylog via Filebeat are also ‘Europe/London’ timezone.
The problem is that Graylog is only showing default UTC timezone for message entries and any time queries, which is an hour behind.
So if the time now is 17:22 “Europe/London”, then Graylog will display and stream messages from 1 hour ago at 16:22. Graylog acts as if these messages are the latest messages from now (current time 17:22), but is actually showing messages from 1 hour ago.
I hope this makes sense, would very much appreciate some feedback on how to resolve this.
Here is a screenshot of what I mean. Timestamp field of Graylog and timestamp of my message are in-sync, but they are from 1 hour ago, even though search time is set to the “last 5 minutes”.
Thanks in advance.