<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk time difference in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635306#M108713</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238496"&gt;@Jackinout9&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I supposed there are two times in the logs and sometimes Splunk doesn't take the correct one, you have to define TIME_PREFIX and TIME_FORMAT.&lt;/P&gt;&lt;P&gt;could you put the sample logs in the "Insers/Edit Code" Sample box?&lt;/P&gt;&lt;P&gt;I cannot find the regex to extract TIME_PREFIX and TIME_FORMAT.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 21 Mar 2023 13:04:23 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-03-21T13:04:23Z</dc:date>
    <item>
      <title>Why is Splunk showing a time difference?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635268#M108709</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;We are trying to write the props from couple of days&lt;/P&gt;
&lt;P&gt;Issue: splunk showing time difference 4 to 5 hours&lt;/P&gt;
&lt;P&gt;logs are coming from one source with multiple time differences ..&lt;BR /&gt;example 1.&lt;BR /&gt;splunk time 3:48pm, log time 20:48 .&lt;BR /&gt;example 2.&lt;BR /&gt;splunk time 2:24pm log time 18:24.&lt;BR /&gt;time format : 2023-03-10T20:48:11.689534088Z&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if you have any ideas or solutions that could help us out here!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 22:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635268#M108709</guid>
      <dc:creator>Jackinout9</dc:creator>
      <dc:date>2023-03-22T22:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635272#M108711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238496"&gt;@Jackinout9&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share a sample of events, both correctly and not correctly indexed?&lt;/P&gt;&lt;P&gt;maybe the problem is the presence of another time inside the events and the timestamp isn't correctle read.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 10:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635272#M108711</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-21T10:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635273#M108712</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with below props&lt;/P&gt;&lt;P&gt;[ &amp;lt;SOURCETYPE NAME&amp;gt; ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;SHOULD LINEMERGE=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;LINE BREAKER= ([\r\n]+)&amp;nbsp;&lt;/P&gt;&lt;P&gt;NO BINARY CHECK=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;TIME PREFIX="time"&lt;/P&gt;&lt;P&gt;CHARSET=UTF-8&amp;nbsp;&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample logs :&lt;/P&gt;&lt;P&gt;3/10/23&lt;/P&gt;&lt;P&gt;3:48:11.689 PM&lt;/P&gt;&lt;P&gt;{ [-]&lt;/P&gt;&lt;P&gt;log: [20:48:11] [&amp;lt;unknown&amp;gt;][9f9835b5][ExtensionHostConnection] &amp;lt;417845&amp;gt; Extension Host Process exited with code: 0, signal: null.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;stream: stdout&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;time: 2023-03-10T20:48:11.689534088Z&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;Show as raw text&lt;/P&gt;&lt;P&gt;3/13/23&lt;/P&gt;&lt;P&gt;2:24:20.526 PM&lt;/P&gt;&lt;P&gt;{ [-]&lt;/P&gt;&lt;P&gt;log: [18:24:20] [unknown][7fafc71d][ManagementConnection] New connection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;stream: stdout&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;time: 2023-03-13T18:24:20, 5264506632&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;Show as raw text&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And also I attached sample pic&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 10:34:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635273#M108712</guid>
      <dc:creator>Jackinout9</dc:creator>
      <dc:date>2023-03-21T10:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635306#M108713</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238496"&gt;@Jackinout9&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I supposed there are two times in the logs and sometimes Splunk doesn't take the correct one, you have to define TIME_PREFIX and TIME_FORMAT.&lt;/P&gt;&lt;P&gt;could you put the sample logs in the "Insers/Edit Code" Sample box?&lt;/P&gt;&lt;P&gt;I cannot find the regex to extract TIME_PREFIX and TIME_FORMAT.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 13:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635306#M108713</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-21T13:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635326#M108716</link>
      <description>&lt;P&gt;One thing is that your log contains "time" as time prefix and "time: " as the string really preceeding the actual timestamp. You could be more precise about that in case you have the word "time" somewhere within the event - you don't want splunk to have more work trying to guess where your timestamp is - the more precise you are, the better and more efficiently splunk works.&lt;/P&gt;&lt;P&gt;Another thing is that you don't have your timeformat defined. Don't leave splunk guessing whether something is a timestamp or not. It's best to have both TIME_PREFIX defined as precisely as possible and TIME_FORMAT set to the timestamp format you're expecting. It makes a huge difference on the input performance.&lt;/P&gt;&lt;P&gt;Next, you don't have MAX_TIMESTAMP_LOOKAHEAD set so it's probably at default 128 characters. Your events seem relatively long and the timestamp isn't placed at the beginning of the event so you might run into trouble if your "data part" of any particular event gets too long and timestamp gets pushed further down the event.&lt;/P&gt;&lt;P&gt;And finally - the timestamps look pretty much OK in terms of the value but shifted in timezones. There can be several reasons - the timezone from the timestamp could have been misinterpreted or you can have wrongly set timezone on your end (in the GUI). Remember that if you're located in a different timezone than reported in the event, the timestamp will get rendered by the GUI according to your timezone. Your events (at least one of them) is supposed to be in Zulu time (GMT). So if you're in another timezone, splunk's GUI may show it as a different hour.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 13:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-showing-a-time-difference/m-p/635326#M108716</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-21T13:57:14Z</dc:date>
    </item>
  </channel>
</rss>

