<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure the Splunk Add-on for Netflow or indexer to capture the correct time stamp for Netflow log data? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201696#M21163</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;
Do you mean you want the time to show in 24h clock instead 12h clock? in other words in your example that would be 19:00 instead of 7PM?&lt;BR /&gt;
If this is the case you can do so by changing the locale. Here are some useful links: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/10643/time-format-for-results-in-en-us-vs-en-gb.html"&gt;https://answers.splunk.com/answers/10643/time-format-for-results-in-en-us-vs-en-gb.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/12509/possible-to-set-user-interface-to-show-24-clock.html"&gt;https://answers.splunk.com/answers/12509/possible-to-set-user-interface-to-show-24-clock.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Dec 2015 18:43:18 GMT</pubDate>
    <dc:creator>ehaddad_splunk</dc:creator>
    <dc:date>2015-12-28T18:43:18Z</dc:date>
    <item>
      <title>How to configure the Splunk Add-on for Netflow or indexer to capture the correct time stamp for Netflow log data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201695#M21162</link>
      <description>&lt;P&gt;Running the Splunk Add-on for Netflow on a Linux server so it can translate the data and forward it to our main Splunk instance running on Windows.  The Netflow data on the Linux box looks something like this for date and time:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1969-12-31 19:00:00,1969-12-31 19:00:00,0.000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This then gets sent over to our indexer (Windows box) and it stamps it with the right date, but the time it stamps it with is 7PM.  What can I adjust in the Netflow add-on or on the indexer to get it to stamp it with the correct times?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 18:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201695#M21162</guid>
      <dc:creator>jeffrey2015</dc:creator>
      <dc:date>2015-12-28T18:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure the Splunk Add-on for Netflow or indexer to capture the correct time stamp for Netflow log data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201696#M21163</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Do you mean you want the time to show in 24h clock instead 12h clock? in other words in your example that would be 19:00 instead of 7PM?&lt;BR /&gt;
If this is the case you can do so by changing the locale. Here are some useful links: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/10643/time-format-for-results-in-en-us-vs-en-gb.html"&gt;https://answers.splunk.com/answers/10643/time-format-for-results-in-en-us-vs-en-gb.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/12509/possible-to-set-user-interface-to-show-24-clock.html"&gt;https://answers.splunk.com/answers/12509/possible-to-set-user-interface-to-show-24-clock.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 18:43:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201696#M21163</guid>
      <dc:creator>ehaddad_splunk</dc:creator>
      <dc:date>2015-12-28T18:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure the Splunk Add-on for Netflow or indexer to capture the correct time stamp for Netflow log data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201697#M21164</link>
      <description>&lt;P&gt;No, it is more like the time itself is way off the line above was captured about 30 minutes ago.  The correct time should have been 1:07PM EST.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 18:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201697#M21164</guid>
      <dc:creator>jeffrey2015</dc:creator>
      <dc:date>2015-12-28T18:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure the Splunk Add-on for Netflow or indexer to capture the correct time stamp for Netflow log data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201698#M21165</link>
      <description>&lt;P&gt;I encountered this same issue when collecting Netflow v9. However, when using v5, it sets the correct timestamp. I think there's an issue with nfdump that comes with this add-on. &lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2016 22:45:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-configure-the-Splunk-Add-on-for-Netflow-or-indexer-to/m-p/201698#M21165</guid>
      <dc:creator>thejohn</dc:creator>
      <dc:date>2016-01-24T22:45:42Z</dc:date>
    </item>
  </channel>
</rss>

