# Delay in the timestamps of logs and events

**URL:** <https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539>\
**Category:** Help\
**Tags:** suricata\
**Created:** [May 26, 2023, 10:27pm UTC](https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539 "2023-05-26T22:27:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diego1](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/diego1/32/2103_2.png) [@Diego1](https://forum.suricata.io/u/Diego1)\
**Post date:** [May 26, 2023, 10:27pm UTC](https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539/1 "2023-05-26T22:27:38Z")

</div>

Hello everyone I hope you can help me.

I have my meerkat server connected to the core of my network, it sends the logs to wazuh through filebeats.

the problem i am having is that the timestamps of the events and alerts on the meerkat server are delayed. This delay increases with the passage of time. for example: I stop the meerkat service, delete the eve.json and fast.log files and restart the service, the timestamps are correctly synchronized, but a few minutes later the delay in timestamps starts again. this delay can increase to even hours.

Thank you very much in advance.

---

<div class="post-metadata">

**Author:** ![IDSTower](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/idstower/32/861_2.png) [@IDSTower](https://forum.suricata.io/u/IDSTower)\
**Post date:** [May 28, 2023, 7:28pm UTC](https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539/2 "2023-05-28T19:28:25Z")

</div>

It seems that filebeat can not send logs fast enough as they are produced, to test if this is the case, enable only a single test rule and see if the same issue continues.

If it is indeed the case, there are several possible options to solve it:

- reduce the number of alerts produced by Suricata
- tune filebeat to send data faster
- tune wazuh to be abe to ingest more data.

---

<div class="post-metadata">

**Author:** ![Diego1](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/diego1/32/2103_2.png) [@Diego1](https://forum.suricata.io/u/Diego1)\
**Post date:** [May 29, 2023, 7:54pm UTC](https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539/3 "2023-05-29T19:54:50Z")

</div>

the delay in the timestamps occurs in the events created by suricata, and consequently not in the elastic server. I have noticed that the delay does not occur during nights and weekends, when there is little traffic. The funny thing is that the meerkat server does not pass 10% cpu usage

---

<div class="post-metadata">

**Author:** ![IDSTower](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/idstower/32/861_2.png) [@IDSTower](https://forum.suricata.io/u/IDSTower)\
**Post date:** [May 30, 2023, 11:28am UTC](https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539/4 "2023-05-30T11:28:17Z")

</div>

Can you attach a sample event (full json) where you see the described delay in the time?

---

<div class="post-metadata">

**Author:** ![Diego1](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/diego1/32/2103_2.png) [@Diego1](https://forum.suricata.io/u/Diego1)\
**Post date:** [May 30, 2023, 10:01pm UTC](https://forum.suricata.io/t/delay-in-the-timestamps-of-logs-and-events/3539/5 "2023-05-30T22:01:08Z")

</div>

after several tests, my solution was to disable http from the suricata.yaml file.  
http:  
enabled: no  
I honestly don’t know the reason why by disabling http the timestamps stay in sync correctly. but unfortunately I will lose visibility of security events related to http.
