<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timestamp and itime does not match in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751688#M119347</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;FortiWeb is configured with NTP.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 15 Aug 2025 05:01:26 GMT</pubDate>
    <dc:creator>phamanh1652</dc:creator>
    <dc:date>2025-08-15T05:01:26Z</dc:date>
    <item>
      <title>timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751476#M119331</link>
      <description>&lt;P&gt;We’re using Splunk Cloud and have configured SC4S to collect logs from FortiAnalyzer, which receives logs from both FortiGate and FortiWeb devices. Most events are processed correctly, with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;timestamp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;itime&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;fields matching. However, we’ve noticed that for some events from FortiWeb, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;timestamp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is ahead of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;itime&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;by approximately 14–15 minutes. Based on our analysis,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;itime&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;reflects the actual time the event occurred.&lt;/P&gt;&lt;P&gt;I’ve reviewed the raw logs and confirmed that all related components are configured to use the same time zone. Has anyone else experienced this issue? Any insights or solutions would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 03:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751476#M119331</guid>
      <dc:creator>phamanh1652</dc:creator>
      <dc:date>2025-08-13T03:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751479#M119333</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260527"&gt;@phamanh1652&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you check system time on fortiweb? Is it configured locally or NTP?&lt;/P&gt;&lt;P&gt;#&lt;A href="https://docs.fortinet.com/document/fortiweb/7.0.11/administration-guide/780143/setting-the-system-time-date" target="_blank"&gt;https://docs.fortinet.com/document/fortiweb/7.0.11/administration-guide/780143/setting-the-system-time-date&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 04:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751479#M119333</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-08-13T04:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751492#M119335</link>
      <description>&lt;P&gt;Such offset (unless you're in a very very unusual time zone) suggests that either:&lt;/P&gt;&lt;P&gt;1) Time on the source is not set correctly or&lt;/P&gt;&lt;P&gt;2) There is an ingestion lag and (this is used as conjunction, not consequence) the timestamp is not parsed from the event itself but assigned from the time of ingestion.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 05:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751492#M119335</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-13T05:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751688#M119347</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;FortiWeb is configured with NTP.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 05:01:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751688#M119347</guid>
      <dc:creator>phamanh1652</dc:creator>
      <dc:date>2025-08-15T05:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751690#M119348</link>
      <description>&lt;P&gt;Btw, what do you mean by itime? Index time? How can it be ahead of the actual time?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 06:04:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751690#M119348</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-15T06:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751694#M119349</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phamanh1652_1-1755240709055.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39973iE11799C6A704389F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phamanh1652_1-1755240709055.png" alt="phamanh1652_1-1755240709055.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is an event of Fortiweb:&lt;/P&gt;&lt;P&gt;event time of splunk 11:53:13&lt;/P&gt;&lt;P&gt;timestamp=1755258793 ==&amp;gt;&amp;nbsp;&lt;SPAN&gt;11:53:13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;itime=1755234267 ==&amp;gt;&amp;nbsp;&lt;SPAN&gt;12:04:27 ==&amp;gt; This is the actual time the event occurred.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 06:57:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751694#M119349</guid>
      <dc:creator>phamanh1652</dc:creator>
      <dc:date>2025-08-15T06:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp and itime does not match</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751740#M119352</link>
      <description>&lt;P&gt;So it's actually the fortigate solution that is "lagging". If the main timestamp for the event should be the itime one, you need to change your props for that sourcetype to use that timestamp instead of the one at timestamp field&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2025 19:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-and-itime-does-not-match/m-p/751740#M119352</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-15T19:10:37Z</dc:date>
    </item>
  </channel>
</rss>

