<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events have wrong timestamp. How to correct time configuration? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183414#M36717</link>
    <description>&lt;P&gt;You should read this &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/Aboutconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/Aboutconfigurationfiles&lt;/A&gt; and the following couple of pages.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Aug 2014 07:54:03 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-08-19T07:54:03Z</dc:date>
    <item>
      <title>Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183404#M36707</link>
      <description>&lt;P&gt;Hi all! Sorry, if this question was already asked by someone, but i'm stuck with a time configuration.&lt;BR /&gt;
So, i just installed Splunk and configured it to listen on UDP port in my network. All hosts send data to it and everything is great, but Splunk shows the wrong time in search results. &lt;BR /&gt;
This is how i see it:&lt;BR /&gt;
&lt;A href="https://www.dropbox.com/s/e4rf3kxete9qgpv/splunk_f.PNG"&gt;https://www.dropbox.com/s/e4rf3kxete9qgpv/splunk_f.PNG&lt;/A&gt;&lt;BR /&gt;
Also Splunk shows me the wrong time on all another hosts. Every time I type another ip - Splunk muss time. &lt;/P&gt;

&lt;P&gt;This my date on server:&lt;BR /&gt;
root@monsrv:~# date&lt;BR /&gt;
Птн Авг 15 09:55:11 IRKT 2014&lt;/P&gt;

&lt;P&gt;What do I need to configure to see the right time in search results? &lt;/P&gt;

&lt;P&gt;Sorry for my bad English. Hope you understand me. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 01:10:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183404#M36707</guid>
      <dc:creator>vetash</dc:creator>
      <dc:date>2014-08-15T01:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183405#M36708</link>
      <description>&lt;P&gt;Post your props.conf configurations.&lt;BR /&gt;
What values you have set for TIME_FORMAT, TIME_PREFIX&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183405#M36708</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2020-09-28T17:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183406#M36709</link>
      <description>&lt;P&gt;Thanks for the reply!&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf:&lt;BR /&gt;
&lt;A href="http://pastebin.com/pDzwZA6G"&gt;http://pastebin.com/pDzwZA6G&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 04:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183406#M36709</guid>
      <dc:creator>vetash</dc:creator>
      <dc:date>2014-08-15T04:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183407#M36710</link>
      <description>&lt;P&gt;The file in etc/system/default is useless to us because it only contains default values.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 07:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183407#M36710</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-08-15T07:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183408#M36711</link>
      <description>&lt;P&gt;Haven't you set your configurations in props.conf file. Your custom configurations should be under /etc/system/local. If you have written a separate app for heavy forwarder or indexer then the props.conf file should be under that app's local directory.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 08:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183408#M36711</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-15T08:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183409#M36712</link>
      <description>&lt;P&gt;Looking at the timestamps in your screenshot it seems this is a timezone issue. What time zone is the source and your user in? Your server seems to be in UTC+9?&lt;/P&gt;

&lt;P&gt;Also, who's prepending the timestamp and host to the syslog event? Is your Splunk doing that, or is that already prepended before it gets to Splunk? If that's prepended before it gets to Splunk, what timezone is that system in?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 09:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183409#M36712</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-08-15T09:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183410#M36713</link>
      <description>&lt;P&gt;Yes UTC+9. Timezone on system is right, also on the hosts who sending logs for splunk. On sceenshot on right side is actual date. Splunk shows incorrect date. (mark as circle &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ) And i have no idea where i need to config it.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 23:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183410#M36713</guid>
      <dc:creator>vetash</dc:creator>
      <dc:date>2014-08-15T23:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183411#M36714</link>
      <description>&lt;P&gt;So where is required props.conf?&lt;BR /&gt;
root@monsrv:~# find /opt/splunk/ -name props.conf&lt;BR /&gt;&lt;BR /&gt;
/opt/splunk/etc/apps/search/default/props.conf&lt;BR /&gt;
/opt/splunk/etc/apps/legacy/default/props.conf&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkLightForwarder/default/props.conf&lt;BR /&gt;
/opt/splunk/etc/apps/learned/local/props.conf&lt;BR /&gt;
/opt/splunk/etc/apps/sample_app/default/props.conf&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 23:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183411#M36714</guid>
      <dc:creator>vetash</dc:creator>
      <dc:date>2014-08-15T23:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183412#M36715</link>
      <description>&lt;P&gt;This is direct from splunk documentation:&lt;BR /&gt;&lt;BR /&gt;
By default, Splunk Enterprise applies time zones using these rules, in this order:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Splunk Enterprise uses any time zone specified in raw event data (for example, PST, -0800).&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Splunk Enterprise uses the value of a TZ attribute set in props.conf, if the event matches the host, source, or source type specified by the stanza.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If an event that arrives at an indexer originated at a forwarder, and both the forwarder and the receiving indexer run Splunk Enterprise 6.0 or later, then Splunk Enterprise uses the time zone that the forwarder provides.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Otherwise, Splunk Enterprise uses the time zone of the server that indexes the event.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Note: If you change the time zone setting in the system Splunk Enterprise runs on, you must restart Splunk Enterprise for it to pick up the change.&lt;/P&gt;

&lt;P&gt;So in your case:&lt;BR /&gt;&lt;BR /&gt;
Point 1 is not applicable as your events do not contain time zone information.&lt;BR /&gt;&lt;BR /&gt;
Point 2 is also not applicable. Since you have not modified any props.conf settings. Also, you are not aware which props.conf contains the settings.&lt;/P&gt;

&lt;P&gt;Then in that case either point 3 or point 4 is applicable. Since you have mentioned in your comment that both the host and the system(receiver) both are in UTC+9 timezone. That timezone is considered for indexing events.&lt;/P&gt;

&lt;P&gt;What you need to do is this:&lt;BR /&gt;&lt;BR /&gt;
Step 1: Create props.conf file under &lt;CODE&gt;/opt/splunk/etc/system/local/&lt;/CODE&gt; directory of your indexer. The full path will look like this &lt;CODE&gt;/opt/splunk/etc/system/local/props.conf&lt;/CODE&gt; on indexer node.&lt;BR /&gt;
Note: You can also create this props.conf file under &lt;CODE&gt;/opt/splunk/etc/apps/&amp;lt;your_app&amp;gt;/local/&lt;/CODE&gt; directory. Here &lt;STRONG&gt;your_app&lt;/STRONG&gt; is the dedicated app that you have created for your indexer node.&lt;/P&gt;

&lt;P&gt;Step 2: Add a stanza with your sourcetype&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Your_Sourcetype]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note: you can have stanza with source, host and sourcetype. I have chosen sourcetype here.&lt;/P&gt;

&lt;P&gt;Step 3: Under that stanza specify the timezone&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Your_Sourcetype]
TZ = UTC
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For more information on setting timezones read &lt;A href="http://"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Applytimezoneoffsetstotimestamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Aug 2014 07:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183412#M36715</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-16T07:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183413#M36716</link>
      <description>&lt;P&gt;I suggest you to read all these:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/HowSplunkextractstimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/HowSplunkextractstimestamps&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Configuretimestamprecognition"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Configuretimestamprecognition&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Configurepositionaltimestampextraction"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Configurepositionaltimestampextraction&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Applytimezoneoffsetstotimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Applytimezoneoffsetstotimestamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Aug 2014 07:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183413#M36716</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-16T07:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183414#M36717</link>
      <description>&lt;P&gt;You should read this &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/Aboutconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/Aboutconfigurationfiles&lt;/A&gt; and the following couple of pages.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2014 07:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183414#M36717</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-08-19T07:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Events have wrong timestamp. How to correct time configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183415#M36718</link>
      <description>&lt;P&gt;HI Strive,&lt;/P&gt;

&lt;P&gt;Thanks for your response, I am facing the same problem but with a weird twist that is this problem is not for all the records, I am having few records (about 100) that are having the this time stamp issue and rest are absolutely fine. Any idea what could possibly be the reason for that?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Vinod. &lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 08:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-have-wrong-timestamp-How-to-correct-time-configuration/m-p/183415#M36718</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-04-09T08:46:41Z</dc:date>
    </item>
  </channel>
</rss>

