<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is status superimposed on our logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621128#M106996</link>
    <description>&lt;P&gt;Are the logs being produced this way by the source system or is this produced by Splunk?&amp;nbsp; If the latter then what is the SPL that produced the output?&lt;/P&gt;&lt;P&gt;FTR. the label_created event is NOT the latest status, it's just last on the list.&amp;nbsp; Note the datetime fields.&amp;nbsp; By default, Splunk displays events in reverse time order so the most recent event is first, not last.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 21:34:53 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-11-16T21:34:53Z</dc:date>
    <item>
      <title>Why is status superimposed on our logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621119#M106994</link>
      <description>&lt;P&gt;Hello Guys!&lt;/P&gt;
&lt;P&gt;Is my first post so sorry if the title is not as specific as it should be&lt;/P&gt;
&lt;P&gt;Look, we have an order tracking report here&lt;/P&gt;
&lt;P&gt;The first status is label created at 10:02&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArtistOfXtreme_0-1668622600908.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22508iADB52F2FDACC84AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArtistOfXtreme_0-1668622600908.png" alt="ArtistOfXtreme_0-1668622600908.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Later, a new status "arrived_at_facility" is added, and even tough that's the latest one. "Label_created" is superimposed&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArtistOfXtreme_1-1668622842942.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22509i9D559C60EBAE554B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArtistOfXtreme_1-1668622842942.png" alt="ArtistOfXtreme_1-1668622842942.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And this continues on and on, the tracking statuses are arriving as normal, but label_created is continued being moved as the latest one.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArtistOfXtreme_2-1668623180224.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22510iF5257876F0419AD5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ArtistOfXtreme_2-1668623180224.png" alt="ArtistOfXtreme_2-1668623180224.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So our tracking report always takes "label_created" as the latest status, instead of something else as "in_transit"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas of what could be wrong with our logs?&lt;/P&gt;
&lt;P&gt;Thanks in advance guys. Any additional info you can need, ask away &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 18:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621119#M106994</guid>
      <dc:creator>ArtistOfXtreme</dc:creator>
      <dc:date>2022-11-16T18:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why is status superimposed on our logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621128#M106996</link>
      <description>&lt;P&gt;Are the logs being produced this way by the source system or is this produced by Splunk?&amp;nbsp; If the latter then what is the SPL that produced the output?&lt;/P&gt;&lt;P&gt;FTR. the label_created event is NOT the latest status, it's just last on the list.&amp;nbsp; Note the datetime fields.&amp;nbsp; By default, Splunk displays events in reverse time order so the most recent event is first, not last.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 21:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621128#M106996</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-16T21:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why is status superimposed on our logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621151#M106997</link>
      <description>&lt;P&gt;Looks like the basic problem is to do with your event timestamping.&lt;/P&gt;&lt;P&gt;Your label created event has the datetime field as 2022-11-09T10:02:42Z, which is a UTC time (because it has Z on the end).&lt;/P&gt;&lt;P&gt;Then the subsequent events have&amp;nbsp;&lt;/P&gt;&lt;P&gt;arrived_at_facility: &lt;STRONG&gt;2022-11-08T17:14:00Z&lt;/STRONG&gt;&lt;BR /&gt;unknown: &lt;STRONG&gt;2022-11-09T00:34:00Z&lt;/STRONG&gt;&lt;BR /&gt;departed_origin_facility: &lt;STRONG&gt;2022-11-08T23:34:00Z&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;and these are all UTC times, so if Splunk is configured to extract the event time from this field, then your events appear to be all out of sync, so as Splunk works on event "_time", the label_created will always be latest.&lt;/P&gt;&lt;P&gt;You need to address the time ingestion timestamping - that will depend on how your data is coming in and the systems that are producing it.&lt;/P&gt;&lt;P&gt;If you cannot address this, then you can treat the "_indextime" field as _time and do something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;my data search
| eval _time=_indextime
more search...&lt;/LI-CODE&gt;&lt;P&gt;but this is not a good practice, unless you have no other option - it will not always be guaranteed to be correct .&lt;/P&gt;&lt;P&gt;If the generating systems are in different time zones, then they appear to be putting incorrect times into the data .&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 23:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621151#M106997</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-11-16T23:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is status superimposed on our logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621189#M107002</link>
      <description>&lt;P&gt;Is this one event (in Splunk terms), i.e. are all the tracking details rewritten to the log whenever there are more details?&lt;/P&gt;&lt;P&gt;If so, you can take the most recent event, with all the details in, break it up into separate splunk events, with the appropriate adjustments to the _time field to get a timeline of tracking detail events&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 07:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-status-superimposed-on-our-logs/m-p/621189#M107002</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-17T07:19:21Z</dc:date>
    </item>
  </channel>
</rss>

