<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time drift between logs and time column in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/681002#M113771</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it's quite possible that your logs have issues in onboarding. It's probably take wrong timezone information from logs or actually cannot find it and for that reason it use some assumptions which seems to to incorrect.&lt;/P&gt;&lt;P&gt;Here&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/files/U0483CQG4/F06PKREDNLW/masa.pdf" target="_blank"&gt;https://splunk-usergroups.slack.com/files/U0483CQG4/F06PKREDNLW/masa.pdf&lt;/A&gt;&amp;nbsp;is excellent picture/flow how data is ingested into splunk and where you should put different configuration options. It's new version of previous MASA diagram.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2024 10:19:05 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-03-18T10:19:05Z</dc:date>
    <item>
      <title>Time drift between logs and time column</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/680920#M113761</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have installed and configured&amp;nbsp; fortiweb for splunk app. The problem is that the time in the log is correct, but the time I receive in the Splunk time column is 7 hours different. It should be mentioned that there is a field in the logs called timezone_dayst that it differs from my time zone by exactly 7 hours.&lt;BR /&gt;I also added TZ = MyTimeZone to the props.conf of the app but problem still exists.&lt;/P&gt;&lt;P&gt;For example, in the image below, it can be seen that the time is equal to 8:37, while the log time is equal to 1:07, and of course timezone_dayst has a drift (-3:30 instead of +3:30).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="imageedit_2_2757226905.gif" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29770i78B2BAE05C6FF34A/image-size/large?v=v2&amp;amp;px=999" role="button" title="imageedit_2_2757226905.gif" alt="imageedit_2_2757226905.gif" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Any ideas are appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 21:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/680920#M113761</guid>
      <dc:creator>sigma</dc:creator>
      <dc:date>2024-03-16T21:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Time drift between logs and time column</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/680943#M113764</link>
      <description>&lt;P&gt;I would recommend making the following checks:&lt;/P&gt;&lt;P&gt;1. The props.conf file is on the indexer machines&lt;BR /&gt;2. The props.conf file is readable by the splunk user&lt;BR /&gt;3. The TZ value in the props.conf file reflects the timezone of the logs&lt;BR /&gt;4. In your Splunk User Preferences in the webUI, your timezone is set to your current timezone&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 08:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/680943#M113764</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-17T08:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Time drift between logs and time column</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/681002#M113771</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it's quite possible that your logs have issues in onboarding. It's probably take wrong timezone information from logs or actually cannot find it and for that reason it use some assumptions which seems to to incorrect.&lt;/P&gt;&lt;P&gt;Here&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/files/U0483CQG4/F06PKREDNLW/masa.pdf" target="_blank"&gt;https://splunk-usergroups.slack.com/files/U0483CQG4/F06PKREDNLW/masa.pdf&lt;/A&gt;&amp;nbsp;is excellent picture/flow how data is ingested into splunk and where you should put different configuration options. It's new version of previous MASA diagram.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:19:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-drift-between-logs-and-time-column/m-p/681002#M113771</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-18T10:19:05Z</dc:date>
    </item>
  </channel>
</rss>

