Docker部署Elasticsearch/Kibana时间显示异常(多2小时)求助
Got it, let's tackle this timezone mismatch issue you're seeing. Since you're on Europe/Berlin (UTC+1/UTC+2 with daylight saving time) and the times are off by exactly 2 hours, this almost certainly ties to how Elasticsearch and Kibana handle timezone settings—even if your host system time checks out. Here's what you can do step by step:
1. Update Elasticsearch Timezone in Docker Compose
The deviantony/docker-elk stack defaults to UTC for Elasticsearch containers, regardless of your host timezone. To fix this:
- Open your
docker-compose.ymlfile - Add the
TZenvironment variable to the Elasticsearch service block:elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:${ELK_VERSION} environment: - TZ=Europe/Berlin # Keep your existing environment variables here - Restart the Elasticsearch container:
docker-compose up -d elasticsearch
2. Configure Kibana's Display Timezone
Kibana might still default to UTC or your browser's timezone (which could be misconfigured). Force it to use Europe/Berlin:
- Log into Kibana
- Go to Management > Advanced Settings
- Search for the
dateFormat:tzsetting - Set its value to
Europe/Berlinand save changes
You can also set the timezone directly in the Kibana Docker service for consistency:
kibana: image: docker.elastic.co/kibana/kibana:${ELK_VERSION} environment: - TZ=Europe/Berlin # Keep your existing environment variables here
Restart Kibana: docker-compose up -d kibana
3. Verify Data Import Timezone Handling
Even if your source JSON has correct times, Elasticsearch might be parsing them as UTC if they don't include timezone info:
- Check your JSON time fields: If they look like
2024-05-20 14:30:00(no timezone), Elasticsearch will treat them as UTC. To fix this, either:- Add timezone offsets to your JSON (e.g.,
2024-05-20T14:30:00+02:00for Berlin DST) - Or update your index mapping to explicitly set the timezone for the time field:
{ "mappings": { "properties": { "your_time_field": { "type": "date", "format": "yyyy-MM-dd HH:mm:ss", "time_zone": "Europe/Berlin" } } } }
- Add timezone offsets to your JSON (e.g.,
4. Confirm Container Timezones
Double-check that your containers are actually using the Europe/Berlin timezone:
- For Elasticsearch:
docker exec -it <your-es-container-name> date - For Kibana:
docker exec -it <your-kibana-container-name> date
Both should show the correct local Berlin time.
After making these changes, reimport your JSON data (or refresh your Kibana index pattern) and the timestamps should align with your actual local time.
内容的提问来源于stack exchange,提问作者carapaece

