how do I cange the syslog timestamps?

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
User avatar
benhank
Posts: 1264
Joined: Tue Apr 12, 2011 12:29 pm

how do I cange the syslog timestamps?

Post by benhank »

Iv'e noticed that NLS will show a timestamp of :
2020-06-01T14:58:20.538Z
But the time stamp of the actual syslog message will be different:
<30>Jun 1 10:58:20

How do I make the timestamp that was generated when the logfile was created the timestamp that is used by NLS?
Proudly running:
NagiosXI 5.4.12 2 node Prod Env 2500 hosts, 13,000 services
Nagiosxi 5.5.7(test env) 2500 hosts, 13,000 services
Nagios Logserver 2 node Prod Env 500 objects sending
Nagios Network Analyser
Nagios Fusion
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: how do I cange the syslog timestamps?

Post by scottwilkerson »

The Z at the end of the timestamp indicated it is showing UTC time which all logs are saved as.

If you are looking at a dashboard able view, you can click the gear icon (configure) top right of the table, then click the Panel tab
Check the "local time" checkbox
Save

This will display the time in you local time instead of UTC

You can then save the dashboard to have it always display this way
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
User avatar
benhank
Posts: 1264
Joined: Tue Apr 12, 2011 12:29 pm

Re: how do I cange the syslog timestamps?

Post by benhank »

That box was already checked but there is still a 4 hour delay:
timestanp.png
You do not have the required permissions to view the files attached to this post.
Proudly running:
NagiosXI 5.4.12 2 node Prod Env 2500 hosts, 13,000 services
Nagiosxi 5.5.7(test env) 2500 hosts, 13,000 services
Nagios Logserver 2 node Prod Env 500 objects sending
Nagios Network Analyser
Nagios Fusion
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: how do I cange the syslog timestamps?

Post by scottwilkerson »

benhank wrote:That box was already checked but there is still a 4 hour delay:
timestanp.png
Oh, yes, it is only changed in the table column (before expanding seen in you screenshot just above View: Table / JSON / Raw), but, when you expand it shows the actual record in Elasticsearch

as far as I am aware there is no way to change this.
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
User avatar
benhank
Posts: 1264
Joined: Tue Apr 12, 2011 12:29 pm

Re: how do I cange the syslog timestamps?

Post by benhank »

ok you can lock this then .
Proudly running:
NagiosXI 5.4.12 2 node Prod Env 2500 hosts, 13,000 services
Nagiosxi 5.5.7(test env) 2500 hosts, 13,000 services
Nagios Logserver 2 node Prod Env 500 objects sending
Nagios Network Analyser
Nagios Fusion
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: how do I cange the syslog timestamps?

Post by scottwilkerson »

benhank wrote:ok you can lock this then .
Locking thread
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
Locked