# \#time-stamp-issuespl

**URL:** https://community.graylog.org/tag/time-stamp-issuespl/8.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Change timestamp in Aggregating table](https://community.graylog.org/t/change-timestamp-in-aggregating-table/36293)

<div class="topic-metadata">

**Author:** [@long.nguyen15](https://community.graylog.org/u/long.nguyen15)\
**Replies:** 1\
**Last updated:** [September 6, 2025, 1:04pm UTC](https://community.graylog.org/t/change-timestamp-in-aggregating-table/36293 "2025-09-06T13:04:38Z")

</div>

Hi everyone, I want to change timestamp from 07:00:00 to 00:00:00 cause log of AD showing wrong days. I had find but nothing issues and infomation before. How can I change please help :frowning:

---

## [Wrong timestamp after updating from 6.1.1 to 6.1.5](https://community.graylog.org/t/wrong-timestamp-after-updating-from-6-1-1-to-6-1-5/34675)

<div class="topic-metadata">

**Author:** [@wilvh](https://community.graylog.org/u/wilvh)\
**Replies:** 12\
**Last updated:** [February 27, 2025, 11:00am UTC](https://community.graylog.org/t/wrong-timestamp-after-updating-from-6-1-1-to-6-1-5/34675 "2025-02-27T11:00:30Z")

</div>

Hi, We have updated Graylog from version 6.1.1 to 6.1.5. Since then, it seems that the timestamp with which messages are recorded is wrong. Let me explain. With version 6.1.1, messages received were saved with a UTC t…

---

## [Assistance Required for Syslog UDP Input Binding Issue in Graylog 6](https://community.graylog.org/t/assistance-required-for-syslog-udp-input-binding-issue-in-graylog-6/33322)

<div class="topic-metadata">

**Author:** [@benashour](https://community.graylog.org/u/benashour)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 9:28am UTC](https://community.graylog.org/t/assistance-required-for-syslog-udp-input-binding-issue-in-graylog-6/33322 "2024-08-26T09:28:32Z")

</div>

am experiencing an issue with Graylog 6 where I am unable to bind a Syslog UDP input to a specific IP address and port. Here are the details: System and Graylog Version: Graylog Version: 6.x Operating System: AlmaLinu…

---

## [Winlogbeat messages pipeline yields wrong timezone](https://community.graylog.org/t/winlogbeat-messages-pipeline-yields-wrong-timezone/33030)

<div class="topic-metadata">

**Author:** [@al\_ex](https://community.graylog.org/u/al_ex)\
**Replies:** 7\
**Last updated:** [July 25, 2024, 9:32pm UTC](https://community.graylog.org/t/winlogbeat-messages-pipeline-yields-wrong-timezone/33030 "2024-07-25T21:32:21Z")

</div>

Hello everyone, I have a pipeline for incoming messages, that adds a field “hour” to each message, so that I can easily filter messages that arrived out of business hours. Unfortunately, this pipeline works differently …

---

## [Timestamps not lining up](https://community.graylog.org/t/timestamps-not-lining-up/30161)

<div class="topic-metadata">

**Author:** [@potvinp](https://community.graylog.org/u/potvinp)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 3:24am UTC](https://community.graylog.org/t/timestamps-not-lining-up/30161 "2023-09-22T03:24:00Z")

</div>

1. Describe your incident: Graylog timestamps do not line up for received logs. The graylog server’s OS is set to UTC and so are the sending clients. For example, below is a log message that is received by Graylog, for …

---

## [Aggregation timestamp reverts to UTC although "timestamp" field is UTC+1](https://community.graylog.org/t/aggregation-timestamp-reverts-to-utc-although-timestamp-field-is-utc-1/28237)

<div class="topic-metadata">

**Author:** [@pastic](https://community.graylog.org/u/pastic)\
**Replies:** 4\
**Last updated:** [March 26, 2023, 3:23pm UTC](https://community.graylog.org/t/aggregation-timestamp-reverts-to-utc-although-timestamp-field-is-utc-1/28237 "2023-03-26T15:23:20Z")

</div>

1. Describe your incident: I’ve configured time settings to UTC+1 and everything has been to my satisfaction. But yesterday I created an aggregation using the metric"timestamp(latest value)" and in that aggregation the …

---

## [Timestamp issue on Slack notifications](https://community.graylog.org/t/timestamp-issue-on-slack-notifications/24776)

<div class="topic-metadata">

**Author:** [@emeneve](https://community.graylog.org/u/emeneve)\
**Replies:** 9\
**Last updated:** [July 22, 2022, 12:18am UTC](https://community.graylog.org/t/timestamp-issue-on-slack-notifications/24776 "2022-07-22T00:18:30Z")

</div>

Hello! I’m having this problem with the timestamp in Slack notifications that not matches with the rest of timestamps (event, log inputs, etc.). I’d like to collect all the logs in my local time (America/Argentina/Buenos…

---

## [Replaced invalid timestamp value in message](https://community.graylog.org/t/replaced-invalid-timestamp-value-in-message/22838)

<div class="topic-metadata">

**Author:** [@davama](https://community.graylog.org/u/davama)\
**Replies:** 9\
**Last updated:** [March 9, 2022, 4:44pm UTC](https://community.graylog.org/t/replaced-invalid-timestamp-value-in-message/22838 "2022-03-09T16:44:14Z")

</div>

1. Describe your incident: After graylog upgrade to v4.2.6 we get these msgs: gl2\_processing\_error Replaced invalid timestamp value in message \<2f44c541-98c8-11ec-88cc-1458d05629d8\> with current time - Value \<2022-02-2…

---

## [Time stamp issues](https://community.graylog.org/t/time-stamp-issues/20330)

<div class="topic-metadata">

**Author:** [@somedude101](https://community.graylog.org/u/somedude101)\
**Replies:** 1\
**Last updated:** [June 30, 2021, 6:41am UTC](https://community.graylog.org/t/time-stamp-issues/20330 "2021-06-30T06:41:06Z")

</div>

Hi there I am looking to get a little help with groking time stamps with Graylog. I understand Elasticsearch and log stash well however I ever used Graylog before. At present I am getting the following errors. I am fair…

---

## [Fortigate changed eventtime from seconds to nanoseconds](https://community.graylog.org/t/fortigate-changed-eventtime-from-seconds-to-nanoseconds/18772)

<div class="topic-metadata">

**Author:** [@Tuumke](https://community.graylog.org/u/Tuumke)\
**Replies:** 1\
**Last updated:** [February 11, 2021, 6:49pm UTC](https://community.graylog.org/t/fortigate-changed-eventtime-from-seconds-to-nanoseconds/18772 "2021-02-11T18:49:40Z")

</div>

I have a pipeline for our fortigates, which worked perfectly. Now we have 2 new firewalls on FortiOS 6.4, and it changes the year to 2038. Doing some research, it seems that FortiOS, from 6.2 and higher, uses nanosecon…

---

## [Messages 2 hours behind](https://community.graylog.org/t/messages-2-hours-behind/16961)

<div class="topic-metadata">

**Author:** [@servicedesk](https://community.graylog.org/u/servicedesk)\
**Replies:** 5\
**Last updated:** [August 31, 2020, 5:29pm UTC](https://community.graylog.org/t/messages-2-hours-behind/16961 "2020-08-31T17:29:04Z")

</div>

Hi We are using Graylog 3.2.4 and in the GUI messages are shown 2 hours later 1 TCP input is created and messages are coming in coming from our firewall on port 5514 the system times show all 3 correctly in the GUI …

---

## [How to split timestamp to date AND time](https://community.graylog.org/t/how-to-split-timestamp-to-date-and-time/14632)

<div class="topic-metadata">

**Author:** [@laakkus](https://community.graylog.org/u/laakkus)\
**Replies:** 2\
**Last updated:** [March 31, 2020, 11:43pm UTC](https://community.graylog.org/t/how-to-split-timestamp-to-date-and-time/14632 "2020-03-31T23:43:19Z")

</div>

Stupid question maybe, but I have scratched my face to this stupid wall enough today… from this: timestamp: 2020-03-25 10:34:00 +02:00 (hower shows it like 2020-03-25T08:34:00.191Z) to these: date: 2020-03-25 time:…

---

## [Timestamp Pipeline/rewrite from Filebeat](https://community.graylog.org/t/timestamp-pipeline-rewrite-from-filebeat/12618)

<div class="topic-metadata">

**Author:** [@abraxas](https://community.graylog.org/u/abraxas)\
**Replies:** 2\
**Last updated:** [November 5, 2019, 5:35pm UTC](https://community.graylog.org/t/timestamp-pipeline-rewrite-from-filebeat/12618 "2019-11-05T17:35:08Z")

</div>

I’m using filebeat to retrieve logs written to a file every few minutes. The logs come in JSON format and are handled properly. There’s a field created called “CreationTime” representing the time in PST. I can convert th…

---

## [How do I upgrade the java-grok graylog jar?](https://community.graylog.org/t/how-do-i-upgrade-the-java-grok-graylog-jar/10867)

<div class="topic-metadata">

**Author:** [@JJ207](https://community.graylog.org/u/JJ207)\
**Replies:** 9\
**Last updated:** [June 21, 2019, 12:58pm UTC](https://community.graylog.org/t/how-do-i-upgrade-the-java-grok-graylog-jar/10867 "2019-06-21T12:58:11Z")

</div>

Hello! I’m having an issue with java grok not allowing commas in date patterns. I found a post here with my exact issue and it appears the solution is to upgrade to java-grok-0.1.9-graylog to resolve this issue. I found…

---

## [Timestamp Replacement Issues (Ingestion timestamp vs log timestamp)](https://community.graylog.org/t/timestamp-replacement-issues-ingestion-timestamp-vs-log-timestamp/9842)

<div class="topic-metadata">

**Author:** [@nom666nom](https://community.graylog.org/u/nom666nom)\
**Replies:** 2\
**Last updated:** [April 6, 2019, 2:24am UTC](https://community.graylog.org/t/timestamp-replacement-issues-ingestion-timestamp-vs-log-timestamp/9842 "2019-04-06T02:24:54Z")

</div>

Essentially I’m trying to replace the ingestion timestamp with the actual timestamp in the logs. I’ve read many of the posts about this but I don’t seem to be making any progress. As you can see in the screenshot below…

---

## [Epoch time fields in pipeline rule](https://community.graylog.org/t/epoch-time-fields-in-pipeline-rule/6948)

<div class="topic-metadata">

**Author:** [@mmurdock](https://community.graylog.org/u/mmurdock)\
**Replies:** 6\
**Last updated:** [September 24, 2018, 6:17pm UTC](https://community.graylog.org/t/epoch-time-fields-in-pipeline-rule/6948 "2018-09-24T18:17:41Z")

</div>

I’m parsing some Cisco UCM call detail records into Graylog using a pipeline rule: rule "parse ucm cdr log" when has\_field("ucm\_type") && to\_string($message.ucm\_type) == "cdr" then let message\_field = to\_string($mes…

---

## [Nginx log access time stamps cannot be converted](https://community.graylog.org/t/nginx-log-access-time-stamps-cannot-be-converted/5325)

<div class="topic-metadata">

**Author:** [@zhou-mfk](https://community.graylog.org/u/zhou-mfk)\
**Replies:** 6\
**Last updated:** [May 28, 2018, 6:08am UTC](https://community.graylog.org/t/nginx-log-access-time-stamps-cannot-be-converted/5325 "2018-05-28T06:08:01Z")

</div>

Hi My nginx log access timestamp cannot be converted. The nginx log format I used is in JSON format, as shown in the figure below: \[image\] In the above figure, I import a past log information, and the timestamp cannot…

---

## [Changing timestamp to servertime recieved](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782)

<div class="topic-metadata">

**Author:** [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Replies:** 8\
**Last updated:** [January 17, 2018, 10:29am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782 "2018-01-17T10:29:41Z")

</div>

is there a easier way to change the timestamp such that it reflects the servertime when the msg was recieved, and not the stamp set by the equipment sending the msg? can i do it in the pipeline, with a rule? im having …

---

## [Setting Timestamp - Piplelines/Rules](https://community.graylog.org/t/setting-timestamp-piplelines-rules/1969)

<div class="topic-metadata">

**Author:** [@ukchris](https://community.graylog.org/u/ukchris)\
**Replies:** 5\
**Last updated:** [August 4, 2017, 10:38pm UTC](https://community.graylog.org/t/setting-timestamp-piplelines-rules/1969 "2017-08-04T22:38:21Z")

</div>

My log format is such that the time stamp is not recognized, as such the (bold) timestamp shows up as the time the message was ingested rather than the actual time. I am parsing out the actual date/time with an extractor…
