<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why isn't my TIME_FORMAT working for this syslog data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/541614#M90581</link>
    <description>&lt;P&gt;I would try explicitly declaring your time zones, as it seems like the time lines up too perfectly to be anything else.&amp;nbsp; Is your timezone UTC -5 perhaps? (or perhaps UTC+5?) &amp;nbsp; From my experience time zones&amp;nbsp; between the time settings of the log source, sourcetype, forwarder, IDX/SH, and user settings the time zones can get quite messy.&amp;nbsp;&amp;nbsp; There's been more than once I assumed everything was properly configured for UTC only to find an error somewhere.&lt;/P&gt;</description>
    <pubDate>Sat, 27 Feb 2021 08:09:22 GMT</pubDate>
    <dc:creator>gbeatty</dc:creator>
    <dc:date>2021-02-27T08:09:22Z</dc:date>
    <item>
      <title>Why isn't my TIME_FORMAT working for this syslog data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/541554#M90577</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;I just configured a new device to send data to a syslog server (w/universal forwarder), but when it shows up in Splunk, the time is incorrect.&amp;nbsp; I have about 30 other devices from different vendors in the same configuration that are working fine.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Here's an example syslog entry:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;&lt;STRONG&gt;2021-02-26T15:35:09-05:00 &lt;/STRONG&gt;&lt;SPAN&gt;XYZ&lt;/SPAN&gt;--&lt;SPAN&gt;-Office-HQ edge&lt;/SPAN&gt;[&lt;SPAN&gt;9076&lt;/SPAN&gt;]&lt;SPAN&gt;: EDGE_NEW_DEVICE: New or updated client device b4:56:e3:a8:91:b5&lt;/SPAN&gt;, &lt;SPAN&gt;ip 10.5.38.0&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;When this log entry shows up in Splunk, the _time is 3:35:09 PM (future) when it should be 10:35:09 AM.&amp;nbsp; The Splunk server (single-node) and device are both in the same time zone with me and other devices on the same syslog server are working fine.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;I've reviewed the following posts, but haven't had much luck&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Search/Abouttimezones" target="_blank" rel="noopener"&gt;How time zones are processed by Splunk&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/Latest/Data/Configuretimestamprecognition" target="_blank" rel="noopener"&gt;Configure timestamp recognition&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf" target="_blank" rel="noopener"&gt;props.conf documentation&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;For example, I set the sourcetype to "velocloud:syslog" for the input and I tried editing the sourcetype so that the TIME_FORMAT=&lt;/FONT&gt;%Y-%m-%dT%H:%M:%S%:z&lt;/P&gt;&lt;P&gt;Unfortunately, this hasn't had any effect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snag_100037a7.png" style="width: 784px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13097i8D46F748AC4B780D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Snag_100037a7.png" alt="Snag_100037a7.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I feel like I'm missing something simple, but I've now spent hours going through everything twice with no luck.&amp;nbsp; Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 16:52:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/541554#M90577</guid>
      <dc:creator>flakshack</dc:creator>
      <dc:date>2021-02-26T16:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my TIME_FORMAT working for this syslog data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/541614#M90581</link>
      <description>&lt;P&gt;I would try explicitly declaring your time zones, as it seems like the time lines up too perfectly to be anything else.&amp;nbsp; Is your timezone UTC -5 perhaps? (or perhaps UTC+5?) &amp;nbsp; From my experience time zones&amp;nbsp; between the time settings of the log source, sourcetype, forwarder, IDX/SH, and user settings the time zones can get quite messy.&amp;nbsp;&amp;nbsp; There's been more than once I assumed everything was properly configured for UTC only to find an error somewhere.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Feb 2021 08:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/541614#M90581</guid>
      <dc:creator>gbeatty</dc:creator>
      <dc:date>2021-02-27T08:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my TIME_FORMAT working for this syslog data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/542596#M90649</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp; All of my systems are located in the same time zone (GMT-5) and I have that set in my user preferences in the Splunk UI.&lt;BR /&gt;&lt;BR /&gt;Per your suggestion, I tried setting the time zone for the sourcetype (via the UI) to +5 and also later to -5.&amp;nbsp; Weirdly, neither setting made any difference in the _time of the log entries in Splunk.&amp;nbsp; In both cases, the time still showed up in the future.&lt;/P&gt;&lt;P&gt;So I decided to change the timestamp format to exclude the -05:00 and also change the time zone and that worked.&lt;/P&gt;&lt;P&gt;Timestamp format:&amp;nbsp; %Y-%m-%dT%H:%M:%S&lt;/P&gt;&lt;P&gt;Time Zone:&amp;nbsp; GMT&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="flakshack_0-1614960004387.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13203i33D8B34594854F07/image-size/large?v=v2&amp;amp;px=999" role="button" title="flakshack_0-1614960004387.png" alt="flakshack_0-1614960004387.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 16:01:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-TIME-FORMAT-working-for-this-syslog-data/m-p/542596#M90649</guid>
      <dc:creator>flakshack</dc:creator>
      <dc:date>2021-03-05T16:01:04Z</dc:date>
    </item>
  </channel>
</rss>

