<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk logs visible after 5hrs:30 mins in splunk UI in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648160#M110192</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Could this help ?&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 07:07:08 GMT</pubDate>
    <dc:creator>Yashprime07</dc:creator>
    <dc:date>2023-06-26T07:07:08Z</dc:date>
    <item>
      <title>Splunk logs visible after 5hrs:30 mins in splunk UI- What could be wrong here?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648153#M110188</link>
      <description>&lt;P&gt;Splunk logs visible after 5hrs:30 mins in splunk UI for example , if I have to see the log of 13:00 to 14:00 , in UI I have to check for 18:00 to 19:00 .&lt;/P&gt;
&lt;P&gt;Here splunk forwarder docker container works as a sidecar container alongside application container with same source volume mounted to both of the containers .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone help what could be wrong here ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 15:42:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648153#M110188</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T15:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648154#M110189</link>
      <description>&lt;P&gt;Could it be a timezone setting mismatch?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 05:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648154#M110189</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-26T05:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648156#M110190</link>
      <description>&lt;P&gt;Somewhere in this setup you have a misconfigured timezone.&lt;/P&gt;&lt;P&gt;First thing to do would be to check what timestamp is really produced by your source. See what timestamp is in the raw event - is it your local timestamp or maybe it's UTC? Does it include timezone information?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 05:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648156#M110190</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-26T05:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648160#M110192</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Could this help ?&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648160#M110192</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T07:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648161#M110193</link>
      <description>&lt;P&gt;Also,&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;we added this part in the application code's Dockerfile&amp;nbsp; too -&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ENV TZ=Asia/Calcutta
RUN ln -snf /usr/share/zoneinfo/${TZ} /etc/localtime &amp;amp;&amp;amp; echo ${TZ} &amp;gt; /etc/timezone&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:09:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648161#M110193</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T07:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648162#M110194</link>
      <description>&lt;P&gt;Inside the container I get this -&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;bash-4.2# date
Mon Jun 26 12:54:44 IST 2023&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648162#M110194</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T07:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648163#M110195</link>
      <description>&lt;P&gt;OK. Apart from one more thing which might be interfering here - what is your user's timezone configured in splunk's webui in your account's preferences?&lt;/P&gt;&lt;P&gt;Anyway, since your sourcetype shows as "auth-too_small" it means that your logs onboarding is not properly configured.&lt;/P&gt;&lt;P&gt;So first things first:&lt;/P&gt;&lt;P&gt;1) Make sure what timestamps your data source produces (in your case - the app). I see "13:09" but what timezone is it in? UTC? Your local TZ? Unfortunately, the timestamp does not - as far as I can see - provide any notion of timezone which is not the best practice. Usually for clarity you'd want to either emit a timestamp containing TZ declaration or at least make sure that data is consistently reported in UTC (you could use local timezone but it might lead to problems with daylight saving if your TZ uses it)&lt;/P&gt;&lt;P&gt;2) Configure the forwarder and receiving indexer accordingly for the sourcetype - configure time recognition parameters - prefix, format, timezone if needed.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648163#M110195</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-26T07:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648164#M110196</link>
      <description>&lt;P&gt;1) It's sending in IST&amp;nbsp;&lt;BR /&gt;2) But I could see _time being 5hrs:30mins greater than the event timestamp, will check these forwarder parameters for that source. But currently it looks like this -&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///var/log/auth/app]
index = auth-signedcall
_meta = stack::&amp;lt;stackname&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:40:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648164#M110196</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T07:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648165#M110197</link>
      <description>&lt;P&gt;Also,&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Checked account preference for timezone, it's this&amp;nbsp; -&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(GMT+05:30) Chennai, Kolkata, Mumbai, New Delhi&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648165#M110197</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T07:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648166#M110198</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said your sourcetype hasn't onboarded correctly. Actually you have just add log file for collection, but You haven't define anything else for it.&lt;/P&gt;&lt;P&gt;You should add sourcetype into your inputs.conf and then with it add needed definitions on your 1st full Splunk Enterprise instance from docker container to indexers. That could be a heavy forwarder or indexer. Ad base sourcetype definitions under [&amp;lt;your sourcetype&amp;gt;] and then e.g. TZ definitions under [host::&amp;lt;your hosts which are in IST TZ&amp;gt;]&lt;/P&gt;&lt;P&gt;Those should fix your issue. But as PickleRick said, there could be still TZ issue when summer time changed to normal time and vice versa. So please check it also after that time.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:50:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648166#M110198</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-26T07:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648209#M110208</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;, the issue was that source type was not specified for this monitor, which breakdowns the events and adds the timezone IST to the events&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 14:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648209#M110208</guid>
      <dc:creator>Yashprime07</dc:creator>
      <dc:date>2023-06-26T14:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs visible after 5hrs:30 mins in splunk UI</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648288#M110216</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256061"&gt;@Yashprime07&lt;/a&gt;&amp;nbsp;- Is your question resolved? If so, kindly accept the answer by clicking on "Accept as Solution" button below the helpful answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk Community Moderator,&lt;/P&gt;&lt;P&gt;Vatsal&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 05:44:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-logs-visible-after-5hrs-30-mins-in-splunk-UI-What-could/m-p/648288#M110216</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-06-27T05:44:52Z</dc:date>
    </item>
  </channel>
</rss>

