<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Event Time is 4 hours ahead of the actual event. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462074#M79753</link>
    <description>&lt;P&gt;Good morning, I have event time showing 4 hours ahead of the actual event. Can anyone point me in the right direction to get the difference corrected? The weird thing that when I run a search on my deployment server it watches he times match, but not on my searchheads.&lt;/P&gt;

&lt;P&gt;Here is the props I am using for one of data sources I am seeing the difference in this is in the o365 app local folder?&lt;/P&gt;

&lt;P&gt;[o365:management:activity]&lt;BR /&gt;
TRUNCATE = 10485760&lt;BR /&gt;
TIME_PREFIX = "CreationTime":\s*"&lt;BR /&gt;
KV_MODE = json&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;The event time is 4 hours ahead of the actual event. &lt;/P&gt;

&lt;P&gt;Please let me know if you need more information? Thank you for your help with this.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:47:54 GMT</pubDate>
    <dc:creator>djreschke</dc:creator>
    <dc:date>2020-09-30T04:47:54Z</dc:date>
    <item>
      <title>Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462074#M79753</link>
      <description>&lt;P&gt;Good morning, I have event time showing 4 hours ahead of the actual event. Can anyone point me in the right direction to get the difference corrected? The weird thing that when I run a search on my deployment server it watches he times match, but not on my searchheads.&lt;/P&gt;

&lt;P&gt;Here is the props I am using for one of data sources I am seeing the difference in this is in the o365 app local folder?&lt;/P&gt;

&lt;P&gt;[o365:management:activity]&lt;BR /&gt;
TRUNCATE = 10485760&lt;BR /&gt;
TIME_PREFIX = "CreationTime":\s*"&lt;BR /&gt;
KV_MODE = json&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;The event time is 4 hours ahead of the actual event. &lt;/P&gt;

&lt;P&gt;Please let me know if you need more information? Thank you for your help with this.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:47:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462074#M79753</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-09-30T04:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462075#M79754</link>
      <description>&lt;P&gt;Make sure the time zone setting accurately reflects where the event occurs.  If the event timestamp is actually in UTC, then "US/Eastern" will make it look 4 hours ahead of time.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 12:33:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462075#M79754</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-31T12:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462076#M79755</link>
      <description>&lt;P&gt;@richgalloway&lt;BR /&gt;
_time: 2020-03-31 12:38:29&lt;BR /&gt;&lt;BR /&gt;
CreationTime: 2020-03-31T08:38:29&lt;/P&gt;

&lt;P&gt;The events are occuring in the US/Eastern - The props above changed the creation time from UTC to EST. Not the event time is showing 4 hours ahead. &lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 12:42:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462076#M79755</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-03-31T12:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462077#M79756</link>
      <description>&lt;P&gt;Have you checked the time zone selection for your Splunk account?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 12:56:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462077#M79756</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-31T12:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462078#M79757</link>
      <description>&lt;P&gt;@richgalloway &lt;/P&gt;

&lt;P&gt;There is no timezone preference set in the user-pref.conf for my user name, Should I check anywhere else? Thank you for your help with this.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 13:07:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462078#M79757</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-03-31T13:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462079#M79758</link>
      <description>&lt;P&gt;Click on your name and select Preferences.  Choose your local time zone from the dropdown menu.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 13:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462079#M79758</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-31T13:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462080#M79759</link>
      <description>&lt;P&gt;@richgalloway&lt;/P&gt;

&lt;P&gt;On the one searchhead i changed it to eastern, but after logging out and logging back in, it resets to default. Do i need to look at roles preferences? &lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 13:51:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462080#M79759</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-03-31T13:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462081#M79760</link>
      <description>&lt;P&gt;Time zones are not role-specific.&lt;BR /&gt;
It's not necessary to log out for the time zone to take effect.  Just re-run the search or refresh the browser page.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 14:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462081#M79760</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-31T14:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462082#M79761</link>
      <description>&lt;P&gt;Its not keeping the preference setting when I do that, and it should keep it when I logout and log back in.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 14:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462082#M79761</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-03-31T14:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462083#M79762</link>
      <description>&lt;P&gt;That's a separate issue.&lt;BR /&gt;
When you change your time zone preference, do events display the correct time?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 15:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462083#M79762</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-31T15:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462084#M79763</link>
      <description>&lt;P&gt;No they don't. They did on my other search head, but not for where the current alert is located at. &lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 15:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462084#M79763</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-03-31T15:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462085#M79764</link>
      <description>&lt;P&gt;What's different between the two search heads?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 17:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462085#M79764</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-31T17:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Event Time is 4 hours ahead of the actual event.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462086#M79765</link>
      <description>&lt;P&gt;The only difference is ES is installed on the one that is not working. This alert is created in the search app. &lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 17:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Time-is-4-hours-ahead-of-the-actual-event/m-p/462086#M79765</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2020-03-31T17:42:37Z</dc:date>
    </item>
  </channel>
</rss>

