Timestamp on Log server

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Post Reply
ashahikh
Posts: 1
Joined: Mon Aug 05, 2019 1:38 pm

Timestamp on Log server

Post by ashahikh »

What controls the timestamp of the logs in the collected logs from various sources? We are seeing a mismatch between Nagios server log receipt and the actual source. Where to check any log timestamp settings?
User avatar
swolf
Developer
Posts: 312
Joined: Tue Jun 06, 2017 9:48 am

Re: Timestamp on Log server

Post by swolf »

Hi @ashahikh,

It'd be useful to have more information - could you share a couple of log lines (both on your actual server and in the log server interface) as well as their timezone?

If you want to dig into this on your own, here's what you'll need to know:
1. Log timestamps are saved in Elasticsearch as UTC, after logstash attempts to parse the timestamp/timezone from the log line.
2. If you're not seeing the correct timestamp, you may want to see if timezone information is available in your logs.
3. If you aren't able to set up timezone information or if you don't have control over the format of your log messages, you can also change your logstash configuration. The syslog input has a timezone setting to allow you to assume a different default timezone.

I hope this helps - please let me know if you have any further questions or concerns.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy
Post Reply