<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trigger time is Populate different in incident review tab in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534916#M89737</link>
    <description>&lt;P&gt;first one-&lt;/P&gt;&lt;P&gt;| tstats summariesonly=f allow_old_summaries=t count latest(_time) as _time from datamodel="Change"&lt;BR /&gt;where All_Changes.result_id=4725 by All_Changes.dest All_Changes.action All_Changes.result All_Changes.user All_Changes.Account_Management.src_user&lt;BR /&gt;| rename All_Changes.* as * , Account_Management.* as * | convert timeformat="%Y/%m/%d %T" ctime(_time) as _time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2nd one-&lt;/P&gt;&lt;P&gt;| tstats summariesonly=f allow_old_summaries=t count latest(_time) as _time from datamodel="Change"&lt;BR /&gt;where All_Changes.result_id=4722 by All_Changes.dest All_Changes.action All_Changes.result All_Changes.user All_Changes.Account_Management.src_user&lt;BR /&gt;| rename All_Changes.* as * , Account_Management.* as * | convert timeformat="%Y/%m/%d %T" ctime(_time) as _time&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2021 07:49:43 GMT</pubDate>
    <dc:creator>sahiltcs1</dc:creator>
    <dc:date>2021-01-06T07:49:43Z</dc:date>
    <item>
      <title>Trigger time is Populate different in incident review tab</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534878#M89732</link>
      <description>&lt;P&gt;We have created two use cases and set up correlation search, Trigger time is every 10 minutes.&lt;/P&gt;&lt;P&gt;When notable event generate in incident review tab, What we observer there is fluctuation in time, trigger time and notable event time are different.&lt;/P&gt;&lt;P&gt;Please refer below screenshot for time difference highlighted.&lt;/P&gt;&lt;P&gt;Trigger time:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;&lt;STRONG&gt;1/6/21 4:06:45.000 AM&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ir-row-hover-field ir-row-float-left"&gt;&lt;DIV class="ir-row-hover-field ir-row-float-left"&gt;Audit&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ir-row-hover-field ir-row-float-left"&gt;User Account x was Locked out by Host&lt;DIV class="ir-row-show-on-hover ir-row-float-inherit"&gt;&amp;nbsp;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="ir-event-module-title ir-header"&gt;Adaptive Responses:&amp;nbsp;&lt;DIV class="adaptive-response-list splunk-view AdaptiveResponseActionListView"&gt;Response Mode Time User Status &lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://pci-gfs-wow.splunkcloud.com/en-US/app/Splunk_DA-ESS_PCICompliance/search?earliest=1609826855&amp;amp;latest=1609827455&amp;amp;q=tag%3Dmodaction_result%20orig_sid=scheduler_cnNhd2FudEB0Y3Mud29vbHdvcnRocy5jb20uYXU_U3BsdW5rX0RBLUVTU19QQ0lDb21wbGlhbmNl__RMD5aca07d52279ff4f2_at_1609827000_82749%20orig_rid=0%20orig_action_name=notable" target="_blank" rel="noopener"&gt;Notable&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;saved&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;&lt;STRONG&gt;2021-01-05T17:12:35+1100&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;I&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;success&lt;/SPAN&gt;&lt;/I&gt;&lt;/I&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to understand why there is time difference?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sahil&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 06 Jan 2021 02:54:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534878#M89732</guid>
      <dc:creator>sahiltcs1</dc:creator>
      <dc:date>2021-01-06T02:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger time is Populate different in incident review tab</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534886#M89733</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229169"&gt;@sahiltcs1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;On your sample Trigger time and Notable times are shown in different time zones. I assume your question is this &amp;nbsp;~6 minutes delay on notable event time.&lt;/P&gt;&lt;P&gt;Since you are running correlation search on every 10 minutes, I assume your time range is something like &lt;A href="mailto:-10m@m" target="_blank"&gt;-10m@m&lt;/A&gt;&amp;nbsp;. Incident Review tab shows the &lt;STRONG&gt;actual event time&lt;/STRONG&gt; that caused that notable. But notable time is the time that your correlation search finalizes by finding a result.&lt;/P&gt;&lt;P&gt;That is why it is normal that this time can be 0 to 10m before the notable event creation time. &amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 05:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534886#M89733</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-06T05:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger time is Populate different in incident review tab</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534911#M89735</link>
      <description>&lt;P&gt;I don't think so its time zone issue, because other use cases we set up same condition and and in that use case we can see same time&amp;nbsp; there is no delay, But for this use case we are facing this issues&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 07:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534911#M89735</guid>
      <dc:creator>sahiltcs1</dc:creator>
      <dc:date>2021-01-06T07:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger time is Populate different in incident review tab</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534914#M89736</link>
      <description>&lt;P&gt;If you can share your correlation search maybe we can investigate better.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 07:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534914#M89736</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-06T07:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger time is Populate different in incident review tab</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534916#M89737</link>
      <description>&lt;P&gt;first one-&lt;/P&gt;&lt;P&gt;| tstats summariesonly=f allow_old_summaries=t count latest(_time) as _time from datamodel="Change"&lt;BR /&gt;where All_Changes.result_id=4725 by All_Changes.dest All_Changes.action All_Changes.result All_Changes.user All_Changes.Account_Management.src_user&lt;BR /&gt;| rename All_Changes.* as * , Account_Management.* as * | convert timeformat="%Y/%m/%d %T" ctime(_time) as _time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2nd one-&lt;/P&gt;&lt;P&gt;| tstats summariesonly=f allow_old_summaries=t count latest(_time) as _time from datamodel="Change"&lt;BR /&gt;where All_Changes.result_id=4722 by All_Changes.dest All_Changes.action All_Changes.result All_Changes.user All_Changes.Account_Management.src_user&lt;BR /&gt;| rename All_Changes.* as * , Account_Management.* as * | convert timeformat="%Y/%m/%d %T" ctime(_time) as _time&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 07:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534916#M89737</guid>
      <dc:creator>sahiltcs1</dc:creator>
      <dc:date>2021-01-06T07:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger time is Populate different in incident review tab</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534920#M89739</link>
      <description>&lt;P&gt;The only think I can suggest is there may be a wrong timestamped event on EventID=4725 or 4722. Since you are using "latest(_time) as _time" it will try to get the latest event sorted by _time. Please check if the correlation search that creates mismatched times has wrong timestamped data. You should be see this by running these searches and checking _time field.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 08:08:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-time-is-Populate-different-in-incident-review-tab/m-p/534920#M89739</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-06T08:08:46Z</dc:date>
    </item>
  </channel>
</rss>

