<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk detecting the wrong timestamp for SUSE Linux Syslog when using a universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201128#M39751</link>
    <description>&lt;P&gt;Thanks for the response. I also want to use the timestamp inside the event and the use of DATETIME_CONFIG=CURRENT was for testing. Below is the details of the syslog event which comes to splunk indexer via universal forwarder.  In the event, date time is coming exactly after the IP address. The IP address is 172.5.41.12 and date is Aug 30 an time is 10.18.43. Unfortunately the year is not in the event and splunk detects the last bit of IP as the year which is 12 as 2012. &lt;/P&gt;

&lt;P&gt;2012-08-30 13:18:44 08/30/2015 13:18:44 local   172.5.41.12 udp:514 linux_secure    Aug 30 13:18:44 172.5.41.12 Aug 30 10:18:43 bccdb 13:18:13 Checkpoint Statistics - Avg. Txn Block Time 0.000, # Txns blocked 0, Plog used 2, Llog used 2&lt;/P&gt;</description>
    <pubDate>Mon, 31 Aug 2015 06:51:22 GMT</pubDate>
    <dc:creator>kpsajin</dc:creator>
    <dc:date>2015-08-31T06:51:22Z</dc:date>
    <item>
      <title>Why is Splunk detecting the wrong timestamp for SUSE Linux Syslog when using a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201126#M39749</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have configured SUSE linux servers to send the syslogs to a Universal Forwarder. We found a very strange issue while the logs are indexed. Splunk is detecting the wrong year in the time stamp. &lt;/P&gt;

&lt;P&gt;For example: If the linux server IP is 172.20.41.11, Splunk detects the year in the time stamp as 2011. If the IP is x.x.x.12, it detects year as 2012. If the IP is x.x.x.16 or x.x.x.17 or anything above 15, it detects as 2015. &lt;/P&gt;

&lt;P&gt;I have tried to forward syslogs to Splunk Indexer directly instead of a universal forwarder and the time stamp is perfect. I  tried to set DATETIME_CONFIG=CURRENT in props.conf in the indexer for the linux source types, but still no luck when the logs are coming through the forwarder. Can someone help to find a solution? &lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2015 10:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201126#M39749</guid>
      <dc:creator>kpsajin</dc:creator>
      <dc:date>2015-08-30T10:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk detecting the wrong timestamp for SUSE Linux Syslog when using a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201127#M39750</link>
      <description>&lt;P&gt;For your UF using syslog, the timestamping will be done by the Indexer so if you would like to use &lt;CODE&gt;DATETIME_CONFIG=CURRENT&lt;/CODE&gt; (which I would advise against; I would always use the timestamp inside the events), then you would put this in &lt;CODE&gt;props.conf&lt;/CODE&gt; on your Indexers and restart the Splunk instances on each one and then look for events that come in &lt;EM&gt;after&lt;/EM&gt; that time to see if these now are timestamped correctly.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2015 14:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201127#M39750</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-30T14:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk detecting the wrong timestamp for SUSE Linux Syslog when using a universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201128#M39751</link>
      <description>&lt;P&gt;Thanks for the response. I also want to use the timestamp inside the event and the use of DATETIME_CONFIG=CURRENT was for testing. Below is the details of the syslog event which comes to splunk indexer via universal forwarder.  In the event, date time is coming exactly after the IP address. The IP address is 172.5.41.12 and date is Aug 30 an time is 10.18.43. Unfortunately the year is not in the event and splunk detects the last bit of IP as the year which is 12 as 2012. &lt;/P&gt;

&lt;P&gt;2012-08-30 13:18:44 08/30/2015 13:18:44 local   172.5.41.12 udp:514 linux_secure    Aug 30 13:18:44 172.5.41.12 Aug 30 10:18:43 bccdb 13:18:13 Checkpoint Statistics - Avg. Txn Block Time 0.000, # Txns blocked 0, Plog used 2, Llog used 2&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 06:51:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-detecting-the-wrong-timestamp-for-SUSE-Linux/m-p/201128#M39751</guid>
      <dc:creator>kpsajin</dc:creator>
      <dc:date>2015-08-31T06:51:22Z</dc:date>
    </item>
  </channel>
</rss>

