@timestamp value is in some random tz
Posted: Thu Mar 19, 2026 12:13 pm
Trialing Log server as a potential SIEM solution.
All the @timestamps are off. I’ve followed the documentation, our log server TZ set correctly, but in the log tables the @timestamp field is set to UTC+9. The Cluster Timezone is set to UTC-8 Pacific Time (US & Canada).
An example is attached. The 'TimeGenerated' and 'ReceiveTime' fields are from the syslog message and correspond within a few seconds of when the entry actually shows up in NLS.
Our TZ is PST8PDT, and the @timestamp field is logging entries in UTC+9
@alder:/var/log/net$ timedatectl
Local time: Thu 2026-03-19 10:10:41 PDT
Universal time: Thu 2026-03-19 17:10:41 UTC
RTC time: Thu 2026-03-19 17:10:41
Time zone: America/Los_Angeles (PDT, -0700)
Network time on: yes
NTP synchronized: yes
RTC in local TZ: no
All the @timestamps are off. I’ve followed the documentation, our log server TZ set correctly, but in the log tables the @timestamp field is set to UTC+9. The Cluster Timezone is set to UTC-8 Pacific Time (US & Canada).
An example is attached. The 'TimeGenerated' and 'ReceiveTime' fields are from the syslog message and correspond within a few seconds of when the entry actually shows up in NLS.
Our TZ is PST8PDT, and the @timestamp field is logging entries in UTC+9
@alder:/var/log/net$ timedatectl
Local time: Thu 2026-03-19 10:10:41 PDT
Universal time: Thu 2026-03-19 17:10:41 UTC
RTC time: Thu 2026-03-19 17:10:41
Time zone: America/Los_Angeles (PDT, -0700)
Network time on: yes
NTP synchronized: yes
RTC in local TZ: no