You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Logstash中为@timestamp字段正确配置时区?

Fixing Timezone Conversion from event_date to @timestamp in Logstash

Let's start with a key point that's probably tripping you up: Elasticsearch stores the @timestamp field in UTC by default—this is a standard best practice to avoid timezone chaos across systems. The 2018-10-20T09:23:46.000Z you're seeing is actually the correct UTC conversion of your Turkish local time, since Turkey (Europe/Istanbul) was UTC+3 back in October 2018. 12:23:46 UTC+3 minus 3 hours equals 09:23:46 UTC, which lines up perfectly.

Your second configuration is actually correct, but let's break this down clearly:

Correct Date Plugin Configuration

You need to explicitly tell Logstash that your event_date value is in the Turkish timezone so it can convert it properly to UTC for @timestamp. Here's the working config:

date {
  match => [ "event_date", "yyyy-MM-dd HH:mm:ss" ]
  timezone => "Europe/Istanbul"
  target => "@timestamp"
}

Why the Time Difference?

  • Your event_date is local Turkish time: 2018-10-20 12:23:46 (UTC+3)
  • Logstash converts this to UTC for storage in @timestamp: 2018-10-20T09:23:46.000Z

This isn't a bug—it's how timezone-aware time storage works. The UTC value is what should live in Elasticsearch to maintain consistency across different systems and timezones.

Want to See Turkish Time in Your Visualizations?

If you want to view the time in Turkish timezone (instead of UTC) in tools like Kibana, don't modify the @timestamp storage. Instead, adjust the display settings in your visualization tool:

  • In Kibana: Go to Stack Management → Advanced Settings, find the dateFormat:tz option, and set it to Europe/Istanbul. All timestamps will now display in your local Turkish timezone while keeping the underlying UTC storage intact.

Quick Validation Trick

To confirm the conversion is working correctly, you can add a quick snippet to your Logstash config to create a field that shows the converted time back in Turkish timezone:

mutate {
  add_field => { "local_timestamp" => "%{@timestamp}" }
}
ruby {
  code => 'event.set("local_timestamp", event.get("local_timestamp").in_time_zone("Europe/Istanbul").strftime("%Y-%m-%d %H:%M:%S"))'
}

You'll see that local_timestamp matches your original event_date value, proving the conversion is accurate.

内容的提问来源于stack exchange,提问作者Orkun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 05:09:10