Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Time-Zone Difference between elastic and wazuh backup files #14463

Open
ThepoisonedApple opened this issue Aug 2, 2022 · 0 comments
Open

Time-Zone Difference between elastic and wazuh backup files #14463

ThepoisonedApple opened this issue Aug 2, 2022 · 0 comments

Comments

@ThepoisonedApple
Copy link

|Wazuh version|Component|Install type|Install method|Platform|Timezone|
|4.3.6|wazuh-manager|Manager|Packages|Debian10|+03|

Hello,
There is a difference between wazuh-manager and opensearch timezones.Wazuh uses local timezone and creates json.gz files at 00:00 every day.But elastic works with universal time.So if i want to delete one day i have to delete data from two indexes.One have 21 hour another have 3 hour and this indexes will have another day's data.When searching there is no problem kibana will get timezone data from browser and applies.

There is no problem when search on dashboard or api.Our problem we have several years of data stored as json.gz .
We deleted them from opensearch because dont need to search frequently.But when we need to restore one day we saw that created 2 indexes.

Recreate the issue step by step:

1-)Run wazuh in a local time configured server for one day.
2-)Use recovery to json.gz in another empty wazuh cluster.
3-)Discover that days data.(there wont be a problem)
4-)Look created indexes.(There will be two indexes)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants