<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event Log time and Indexed time is different in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608209#M105543</link>
    <description>&lt;P&gt;This may help you.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Q5EWCT79nZ4" target="_blank"&gt;https://www.youtube.com/watch?v=Q5EWCT79nZ4&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 03:39:55 GMT</pubDate>
    <dc:creator>chaker</dc:creator>
    <dc:date>2022-08-04T03:39:55Z</dc:date>
    <item>
      <title>Why is Event Log time and Indexed time different?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608198#M105541</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;Please check with below screenshot&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_1-1659577705527.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20844i0DDB33590148BCFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_1-1659577705527.png" alt="Atchyuth_P_1-1659577705527.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The indexed time and event log time both are different. Kindly let me know the solution to fix this error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 14:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608198#M105541</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-08-04T14:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608207#M105542</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You will need to provide timestamp extraction settings to correctly identify that time stamp, if none of the pre trained source types are picking it up.&lt;/P&gt;&lt;P&gt;I suggest you try to add that data using different sourcetypes in the data preview tool, to see which on extracts your time stamp, then use that setting in your own sourcetype settings.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Data/HowSplunkextractstimestamps" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Data/HowSplunkextractstimestamps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Propsconf#Timestamp_extraction_configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Propsconf#Timestamp_extraction_configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 03:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608207#M105542</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2022-08-04T03:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608209#M105543</link>
      <description>&lt;P&gt;This may help you.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Q5EWCT79nZ4" target="_blank"&gt;https://www.youtube.com/watch?v=Q5EWCT79nZ4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 03:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608209#M105543</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2022-08-04T03:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608218#M105544</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this means thet there's a parsing error.&lt;/P&gt;&lt;P&gt;Could your share a sample of your logs to find the correct configuration?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 06:43:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608218#M105544</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-04T06:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608372#M105564</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the below screenshot for reference.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_0-1659666952599.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20869i4759861AA3EAE1BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_0-1659666952599.png" alt="Atchyuth_P_0-1659666952599.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have applied the MAX_DAYS_AGO setting in Splunk it identified the Y-m-d but was unable to find out the exact hours, minutes, seconds&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_1-1659667143760.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20870i5647913F71A18685/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_1-1659667143760.png" alt="Atchyuth_P_1-1659667143760.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have tried with the TZ setting but was unable to solve it.&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 02:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608372#M105564</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-08-05T02:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608378#M105565</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/165039"&gt;@chaker&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much. I have learned a lot about Splunk while watching your videos and those helped me to shift my career transition.&lt;/P&gt;&lt;P&gt;Please check the below screenshot for reference.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_1-1659667441524.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20872iFB8F0EDBDE118042/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_1-1659667441524.png" alt="Atchyuth_P_1-1659667441524.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have applied the MAX_DAYS_AGO setting in Splunk it identified the Y-m-d but was unable to find out the exact hours, minutes, seconds&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Atchyuth_P_2-1659667567922.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20873i1B32386574ACA0E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Atchyuth_P_2-1659667567922.png" alt="Atchyuth_P_2-1659667567922.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have tried with the TZ setting but was unable to solve it.&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 02:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608378#M105565</guid>
      <dc:creator>Atchyuth_P</dc:creator>
      <dc:date>2022-08-05T02:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608400#M105567</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please share your logs as text in the "Insert/Edit Code Sample" otherwise I cannot use them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 07:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608400#M105567</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-05T07:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Event Log time and Indexed time is different</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608466#M105569</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237468"&gt;@Atchyuth_P&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;anyway, please try in your props.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
TIME_PREFIX = ^\d+\.\d+\.\d+\.\d+\s+w\s+\w+\s+\[
TIME_FORMAT = %Y-%m-%d \s+\H:|M:|S.%6N
MAX_TIMESTAMP_LOOKAHEAD = 26&lt;/LI-CODE&gt;&lt;P&gt;This props.conf must be located on Indexers or (if present) On Heavy Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 13:57:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608466#M105569</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-05T13:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Event Log time and Indexed time different?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608509#M105571</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DSCN0012.jpg" style="width: 640px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20903i6DBDBFC4531C834F/image-size/large?v=v2&amp;amp;px=999" role="button" title="DSCN0012.jpg" alt="DSCN0012.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 16:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Event-Log-time-and-Indexed-time-different/m-p/608509#M105571</guid>
      <dc:creator>wapese3400</dc:creator>
      <dc:date>2022-08-05T16:07:48Z</dc:date>
    </item>
  </channel>
</rss>

