<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time Stamp i(All time vs 15 min) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166492#M33740</link>
    <description>&lt;P&gt;Splunk thinks your system time is GMT, so since your user timezone is set to EST it is adjusting the displayed time.  You can check this by setting your user timezone to GMT.&lt;BR /&gt;
I'm also curious about the timestamps in the &lt;CODE&gt;_raw&lt;/CODE&gt; output&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2014 20:22:21 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2014-02-26T20:22:21Z</dc:date>
    <item>
      <title>Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166485#M33733</link>
      <description>&lt;P&gt;When I do a search on my search head for all time, I see correct time stamps in standard EST. When I do a 15 minute search, I see time stamps from 5 hours ago. &lt;/P&gt;

&lt;P&gt;My search head and indexer are both set to CST on the OS, and the logs are coming in in EST which has been defined in props.conf. &lt;/P&gt;

&lt;P&gt;Does anyone know why this could be happening? &lt;/P&gt;

&lt;P&gt;This is an image of my sourcetype time stamps, vs my system clock (CST). &lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/ims_timestamp.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 14:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166485#M33733</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T14:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166486#M33734</link>
      <description>&lt;P&gt;What is your splunk user timezone property set to?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 14:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166486#M33734</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-26T14:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166487#M33735</link>
      <description>&lt;P&gt;It is set to EST&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 14:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166487#M33735</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T14:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166488#M33736</link>
      <description>&lt;P&gt;This is also happening on any user that logs into my search head.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 15:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166488#M33736</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T15:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166489#M33737</link>
      <description>&lt;P&gt;Is this for all data, or just certain sources?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 15:56:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166489#M33737</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-26T15:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166490#M33738</link>
      <description>&lt;P&gt;This is happening on all sourcetypes. I'm sure there is a global setting somewhere that I am missing, but I couldn't tell you what it is to save my life.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 16:03:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166490#M33738</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T16:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166491#M33739</link>
      <description>&lt;P&gt;That includes windows Perfmon&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 16:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166491#M33739</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T16:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166492#M33740</link>
      <description>&lt;P&gt;Splunk thinks your system time is GMT, so since your user timezone is set to EST it is adjusting the displayed time.  You can check this by setting your user timezone to GMT.&lt;BR /&gt;
I'm also curious about the timestamps in the &lt;CODE&gt;_raw&lt;/CODE&gt; output&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:22:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166492#M33740</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-26T20:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166493#M33741</link>
      <description>&lt;P&gt;Raw print of an event for 15 minute search of a sourcetype:&lt;/P&gt;

&lt;P&gt;Query:&lt;BR /&gt;
sourcetype=&lt;SRCNAME&gt; | table _raw&lt;/SRCNAME&gt;&lt;/P&gt;

&lt;P&gt;INFO &lt;FIRMID&gt;&lt;FIRMNAME&gt;&lt;USERID&gt;&lt;USERNAME&gt;&lt;PROCESSNAME&gt;&lt;PID&gt;&lt;TID&gt;&lt;TIME&gt;&lt;BR /&gt;
&lt;CALLERNAME&gt;&lt;MESSAGE&gt;
UserSession for * [7] user Adapter [1]&amp;gt;&lt;EXCEPTION&gt;&lt;/EXCEPTION&gt;&lt;/MESSAGE&gt;&lt;/CALLERNAME&gt;&lt;/TIME&gt;&lt;/TID&gt;&lt;/PID&gt;&lt;/PROCESSNAME&gt;&lt;/USERNAME&gt;&lt;/USERID&gt;&lt;/FIRMNAME&gt;&lt;/FIRMID&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:29:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166493#M33741</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T20:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166494#M33742</link>
      <description>&lt;P&gt;If this is a recent event, then the timestamp is GMT.&lt;BR /&gt;
Are you configuring the TZ in props.conf on the indexer by host?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:43:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166494#M33742</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-26T20:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166495#M33743</link>
      <description>&lt;P&gt;negative... but when I looked at my OS on both the indexer and the SH it was in GMT. I set it to CST during install, and didnt' check it after that. I am reconfiguring it now to be in EST and we will see what happens.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:58:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166495#M33743</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T20:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166496#M33744</link>
      <description>&lt;P&gt;In lukejadamec's comments, he mentioned that splunk thought my system time was off. I set the time zone and time settings manually during OS installation, but never checked them after that. When i did, they reflected GMT time. &lt;/P&gt;

&lt;P&gt;I adjusted these settings to EST, and all timestamps are current now, and the issue has been resolved. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 21:42:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166496#M33744</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2014-02-26T21:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp i(All time vs 15 min)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166497#M33745</link>
      <description>&lt;P&gt;Yea.  This was starting to give me heartburn &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 22:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Stamp-i-All-time-vs-15-min/m-p/166497#M33745</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-26T22:13:28Z</dc:date>
    </item>
  </channel>
</rss>

