<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timestamp issue in Security</title>
    <link>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363948#M12791</link>
    <description>&lt;P&gt;I figured it out...&lt;/P&gt;

&lt;P&gt;[source::/opt/syslog-ng/palo_alto/CSG2-MAIN-FW1/*/messages.txt]&lt;BR /&gt;
TZ = PST&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jan 2018 18:31:25 GMT</pubDate>
    <dc:creator>mcbradford</dc:creator>
    <dc:date>2018-01-02T18:31:25Z</dc:date>
    <item>
      <title>timestamp issue</title>
      <link>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363944#M12787</link>
      <description>&lt;P&gt;I have firewall events coming to my syslog-ng server.  The firewall events are in Central European Timezone, so when the events are indexed, they are showing up in this time (as expected), so about 5 hours in the future when searching.&lt;/P&gt;

&lt;P&gt;I am trying to figure out where to adjust this.  I know the props.conf needs adjusted but where?  I tried to add a props.conf to local within the app on the UF, but this made no change.&lt;/P&gt;

&lt;P&gt;I then tried to add props.conf within local under the firewall app on the indexer, and I stopped getting events all together???&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 17:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363944#M12787</guid>
      <dc:creator>mcbradford</dc:creator>
      <dc:date>2017-12-21T17:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp issue</title>
      <link>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363945#M12788</link>
      <description>&lt;P&gt;So you've UF installed on your syslog-ng server which are sending data directory to Indexer (no intermediate heavy forwarders in between)? If yes, then the props.conf should be updated on Indexers. Can you confirm if you're adding TZ information correctly and within correct sourcetype stanza in your props.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 18:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363945#M12788</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-12-21T18:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp issue</title>
      <link>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363946#M12789</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;In order to understand which props.conf to be configured, it is important to understand the data pipeline, please refer to this link for more information:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Configurationparametersandthedatapipeline" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Configurationparametersandthedatapipeline&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And to answer your question, if your Splunk architecture only has a Splunk UF installed on your syslog-ng and forward logs directly to Splunk indexer, you will need to configure your timestamp configuration in the indexer's props.conf. In certain situations, if you apply the INDEXED_EXTRACTIONS in your Universal Forwarder's props.conf, you will need to configure timestamp extractions on the same props.conf on UF as well.&lt;/P&gt;

&lt;P&gt;If your UF is forwarding data to a Heavy Forwarder before forwarding to the indexer, you will need to configure timestamp configurations on the HF's props.conf.&lt;/P&gt;

&lt;P&gt;Lastly, please review your timestamp configurations for the firewall sourcetype. These are the configurations used for timestamp extractions:&lt;BR /&gt;
- TIME_PREFIX&lt;BR /&gt;
- TIME_FORMAT&lt;BR /&gt;
- MAX_TIMESTAMP_LOOKAHEAD&lt;BR /&gt;
- TZ&lt;BR /&gt;
- DATETIME_CONFIG&lt;/P&gt;

&lt;P&gt;Hope it clears your doubts!&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Benjamin&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363946#M12789</guid>
      <dc:creator>BenTan</dc:creator>
      <dc:date>2020-09-29T17:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp issue</title>
      <link>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363947#M12790</link>
      <description>&lt;P&gt;BenTan,&lt;/P&gt;

&lt;P&gt;Thanks for taking the time to answer my question.  I have 8 firewalls that are in 4 different time zones.&lt;/P&gt;

&lt;P&gt;I will only focus on one for now...&lt;/P&gt;

&lt;P&gt;raw event&lt;/P&gt;

&lt;P&gt;Jan  2 08:40:09 CSG2-MAIN-FW1 1,2018/01/02 08:40:08,011901000724,TRAFFIC,end,1,2018/01/02 08:40:08,10.3.0.63,8.8.8.8,216.85.221.10,8.8.8.8,Standard Outbound Apps,,,ping,vsys1,Trust,Untrust,ethernet1/1,ethernet1/4,Panorama,2018/01/02 08:40:08,149453,6,0,0,0,0,0x500019,icmp,allow,1176,588,588,12,2018/01/02 08:39:57,0,any,0,275058159,0x0,10.0.0.0-10.255.255.255,United States,0,6,6,aged-out,213,0,0,0,,CSG2-MAIN-FW1,from-policy,,,0,,0,,N/A&lt;/P&gt;

&lt;P&gt;Since these are all going to a syslog server, I cannot use the host stanza, so I was going to use the source stanza.&lt;/P&gt;

&lt;P&gt;The source is:&lt;BR /&gt;
/opt/syslog-ng/palo_alto/CSG2-MAIN-FW1/2018-01-02/messages.txt&lt;/P&gt;

&lt;P&gt;I tried:&lt;/P&gt;

&lt;P&gt;[&lt;CODE&gt;source::*CSG2-MAIN-FW1*&lt;/CODE&gt;]&lt;BR /&gt;
TZ = PST&lt;/P&gt;

&lt;P&gt;but it did not work&lt;/P&gt;

&lt;P&gt;I tried:&lt;/P&gt;

&lt;P&gt;[source::.../opt/syslog-ng/palo_alto/CSG2-MAIN-FW1/*]&lt;BR /&gt;
TZ = PST&lt;/P&gt;

&lt;P&gt;but it did not work&lt;/P&gt;

&lt;P&gt;I am making the changes to props.conf located in:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_paloalto/default&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363947#M12790</guid>
      <dc:creator>mcbradford</dc:creator>
      <dc:date>2020-09-29T17:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp issue</title>
      <link>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363948#M12791</link>
      <description>&lt;P&gt;I figured it out...&lt;/P&gt;

&lt;P&gt;[source::/opt/syslog-ng/palo_alto/CSG2-MAIN-FW1/*/messages.txt]&lt;BR /&gt;
TZ = PST&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 18:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/timestamp-issue/m-p/363948#M12791</guid>
      <dc:creator>mcbradford</dc:creator>
      <dc:date>2018-01-02T18:31:25Z</dc:date>
    </item>
  </channel>
</rss>

