<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time is wrong. Events showing in the past (which are present) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671473#M112544</link>
    <description>&lt;P&gt;So this is a new install and new source.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the splunk server there is no props.conf file. I assume I have to create it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Dec 2023 19:09:38 GMT</pubDate>
    <dc:creator>sirsam28</dc:creator>
    <dc:date>2023-12-11T19:09:38Z</dc:date>
    <item>
      <title>Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671467#M112539</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rather new to splunk. I got some logs ingested but they are showing Time incorrectly. I have my TZ set on the UF server, splunk server and in my preferences as EST but I am getting this:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;12/11/23&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8:35:24.000 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;2023-12-11T13:35:24&lt;/SPAN&gt;+&lt;SPAN class=""&gt;00:00&lt;/SPAN&gt; &lt;SPAN class=""&gt;routerXXXXXX&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I look at the field _time I have:&amp;nbsp;&lt;SPAN&gt;2023-12-11T08:35:24.000-05:00&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I suspect the source host or I need a props.conf to fix?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 18:44:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671467#M112539</guid>
      <dc:creator>sirsam28</dc:creator>
      <dc:date>2023-12-11T18:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671469#M112540</link>
      <description>&lt;P&gt;And that seems about right. Your router reports 13:35GMT so Splunk parses it as 13:35GMT and shows it to you in your local time zone.&lt;/P&gt;&lt;P&gt;Your data quality is poor - configure your router to either report proper time zone or proper time (or even better - to report proper time in proper timezone).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 19:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671469#M112540</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-11T19:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671471#M112542</link>
      <description>&lt;P&gt;Please share the props.conf stanza for that sourcetype.&amp;nbsp; It looks like the TIME_FORMAT string may be incorrect.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 19:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671471#M112542</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-11T19:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671473#M112544</link>
      <description>&lt;P&gt;So this is a new install and new source.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the splunk server there is no props.conf file. I assume I have to create it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 19:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671473#M112544</guid>
      <dc:creator>sirsam28</dc:creator>
      <dc:date>2023-12-11T19:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671475#M112545</link>
      <description>&lt;P&gt;Every sourcetype should have a stanza in props.conf.&amp;nbsp; Create a props.conf file if there isn't a local copy already.&lt;/P&gt;&lt;P&gt;The stanza should contain these settings, at a minimum:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE
LINE_BREAKER
TIME_PREFIX
TIME_FORMAT
MAX_TIMESTAMP_LOOKAHEAD
TRUNCATE
EVENT_BREAKER_ENABLE
EVENT_BREAKER&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 20:05:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671475#M112545</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-11T20:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671476#M112546</link>
      <description>&lt;P&gt;Whiile Splunk can sometimes guess the proper settings for the sourcetype (and sometimes - as shown in this case - does it quite well), as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; mentioned - it's good to have the so-called "great eight" defined for each sourcetype to make it work consistently and efficiently.&lt;/P&gt;&lt;P&gt;Having said that - in this particular case your main issue is wrong time in your events!&lt;/P&gt;&lt;P&gt;You have your router's time set to a wrong value. Configure it properly. Whether it's reported as UTC or your local timezone is secondary as long as the proper timezone information is supplied (and in your case it is).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 20:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671476#M112546</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-11T20:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671481#M112549</link>
      <description>&lt;P&gt;So interesting enough, in the router's cli:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;xxxx@router:~ # date&lt;BR /&gt;Mon Dec 11 15:55:57 EST 2023&lt;/P&gt;&lt;P&gt;Also in the GUI showing correctly. I think a props.conf might be the route as it doesnt know how to translate it?&lt;/P&gt;&lt;P&gt;Would anyone be able to help craft an example stanza for it? I just dont want to mess up the logging further&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 21:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671481#M112549</guid>
      <dc:creator>sirsam28</dc:creator>
      <dc:date>2023-12-11T21:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671485#M112550</link>
      <description>&lt;P&gt;Give these settings a go&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%dT%H:%M:%D%:z
MAX_TIMESTAMP_LOOKAHEAD = 30
TRUNCATE = 10000
EVENT_BREAKER_ENABLE = true
EVENT_BREAKER = ([\r\n]+)&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 11 Dec 2023 21:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671485#M112550</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-11T21:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671489#M112552</link>
      <description>&lt;P&gt;That is indeed interesting because supposedly keeping track of the timezome but in the end sending the timestamp with local time but explicitly saying that's UTC is not even a mistake. It's almost a crime. What ingenious piece of equipment is that if you can share this with us?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 22:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671489#M112552</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-11T22:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671562#M112558</link>
      <description>&lt;P&gt;So its a opnsense firewall&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 12:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671562#M112558</guid>
      <dc:creator>sirsam28</dc:creator>
      <dc:date>2023-12-12T12:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671563#M112559</link>
      <description>&lt;P&gt;Thanks for that. I created the file in /opt/splunk/etc/system/local/props.conf as follows:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[default]


[host::router.xxxxxxxx]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%dT%H:%M:%D%:z
MAX_TIMESTAMP_LOOKAHEAD = 30
TRUNCATE = 10000
EVENT_BREAKER_ENABLE = true&lt;/LI-CODE&gt;
&lt;P&gt;I am still getting the descrepency. Perhaps my props.conf file is not the correct format or in the right spot for Splunk to read?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 13:01:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671563#M112559</guid>
      <dc:creator>sirsam28</dc:creator>
      <dc:date>2023-12-12T13:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Time is wrong. Events showing in the past (which are present)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671567#M112560</link>
      <description>&lt;P&gt;On which instance did you install those settings?&amp;nbsp; They should be on the indexers (and heavy forwarders, if you have them).&amp;nbsp; Did you restart the instances after modifying the file?&amp;nbsp; Are you looking at new data?&amp;nbsp; The changes will not affect indexed data.&amp;nbsp; Do you have the correct host name in the stanza?&amp;nbsp; Have you tried using the sourcetype name instead of host?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 13:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-is-wrong-Events-showing-in-the-past-which-are-present/m-p/671567#M112560</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-12T13:19:34Z</dc:date>
    </item>
  </channel>
</rss>

