如何在Logstash中为@timestamp字段正确配置时区?
Let's start with a key point that's probably tripping you up: Elasticsearch stores the @timestamp field in UTC by default—this is a standard best practice to avoid timezone chaos across systems. The 2018-10-20T09:23:46.000Z you're seeing is actually the correct UTC conversion of your Turkish local time, since Turkey (Europe/Istanbul) was UTC+3 back in October 2018. 12:23:46 UTC+3 minus 3 hours equals 09:23:46 UTC, which lines up perfectly.
Your second configuration is actually correct, but let's break this down clearly:
Correct Date Plugin Configuration
You need to explicitly tell Logstash that your event_date value is in the Turkish timezone so it can convert it properly to UTC for @timestamp. Here's the working config:
date { match => [ "event_date", "yyyy-MM-dd HH:mm:ss" ] timezone => "Europe/Istanbul" target => "@timestamp" }
Why the Time Difference?
- Your
event_dateis local Turkish time:2018-10-20 12:23:46(UTC+3) - Logstash converts this to UTC for storage in
@timestamp:2018-10-20T09:23:46.000Z
This isn't a bug—it's how timezone-aware time storage works. The UTC value is what should live in Elasticsearch to maintain consistency across different systems and timezones.
Want to See Turkish Time in Your Visualizations?
If you want to view the time in Turkish timezone (instead of UTC) in tools like Kibana, don't modify the @timestamp storage. Instead, adjust the display settings in your visualization tool:
- In Kibana: Go to Stack Management → Advanced Settings, find the
dateFormat:tzoption, and set it toEurope/Istanbul. All timestamps will now display in your local Turkish timezone while keeping the underlying UTC storage intact.
Quick Validation Trick
To confirm the conversion is working correctly, you can add a quick snippet to your Logstash config to create a field that shows the converted time back in Turkish timezone:
mutate { add_field => { "local_timestamp" => "%{@timestamp}" } } ruby { code => 'event.set("local_timestamp", event.get("local_timestamp").in_time_zone("Europe/Istanbul").strftime("%Y-%m-%d %H:%M:%S"))' }
You'll see that local_timestamp matches your original event_date value, proving the conversion is accurate.
内容的提问来源于stack exchange,提问作者Orkun

