<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What time is displayed in raw splunk logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447221#M95447</link>
    <description>&lt;P&gt;Thanks for the explanation. I am not blaming splunk for anything, just trying to understand so it can utilized in correct manner. &lt;BR /&gt;
With the explanation you are giving, it seems the source log file is logging in EST, that would mean the server which I assumed was in GMT is in fact in EST location. So, I need to change my account settings to EST then, to get consistent logs.&lt;BR /&gt;
I will try this and see if it helps in finding old logs in appropriate date time range.&lt;/P&gt;</description>
    <pubDate>Sat, 16 Mar 2019 17:48:10 GMT</pubDate>
    <dc:creator>gsonal03</dc:creator>
    <dc:date>2019-03-16T17:48:10Z</dc:date>
    <item>
      <title>What time is displayed in raw splunk logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447219#M95445</link>
      <description>&lt;P&gt;I am trying to debug issues related to delay in splunk forwarding or indexing in a separate splunk query "&lt;A href="https://answers.splunk.com/answers/730136/why-are-our-splunk-indexes-not-showing-all-log-ent.html"&gt;https://answers.splunk.com/answers/730136/why-are-our-splunk-indexes-not-showing-all-log-ent.html&lt;/A&gt;. But I would like to understand how the display of raw logs are governed, so opening a new ticket.&lt;/P&gt;

&lt;P&gt;Attached below is a mockup of how I see logs in raw format and account settings. I have my account settings configured to GMT timezone. When I search any logs in raw format, I see each log entry beginning with EST timestamp. When I expand it, I see _time field showing time in GMT format.&lt;BR /&gt;
How and where can I change the settings for the log entry so that it remains consistent and I can debug correct time period to view logs . The servers from where we are forwarding the logs is also in GMT time as far as I know.&lt;BR /&gt;
Time-mockup: &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6728i0875D4C9FDD765F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 16:54:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447219#M95445</guid>
      <dc:creator>gsonal03</dc:creator>
      <dc:date>2019-03-16T16:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: What time is displayed in raw splunk logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447220#M95446</link>
      <description>&lt;P&gt;There is no such thing as &lt;CODE&gt;time displayed in logs&lt;/CODE&gt;; there is only &lt;CODE&gt;text displayed in logs&lt;/CODE&gt; so the thing that you see in the raw event is the unmodified text the way that the event came in.&lt;/P&gt;

&lt;P&gt;Do you see the &lt;CODE&gt;Raw v&lt;/CODE&gt; that is above &lt;CODE&gt;Event&lt;/CODE&gt; that is above your timestamp?&lt;BR /&gt;
Click on that and change it to &lt;CODE&gt;List&lt;/CODE&gt;.  You will then see a new column called &lt;CODE&gt;Time&lt;/CODE&gt; between &lt;CODE&gt;i&lt;/CODE&gt; and &lt;CODE&gt;Event&lt;/CODE&gt; that shows the event's timestamp adjusted to your user's &lt;CODE&gt;Time zone&lt;/CODE&gt; setting.  BTW, &lt;CODE&gt;List&lt;/CODE&gt; is the default so at some point you changed this (or somebody logged in as you), so don't blame Splunk!&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 17:32:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447220#M95446</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-16T17:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: What time is displayed in raw splunk logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447221#M95447</link>
      <description>&lt;P&gt;Thanks for the explanation. I am not blaming splunk for anything, just trying to understand so it can utilized in correct manner. &lt;BR /&gt;
With the explanation you are giving, it seems the source log file is logging in EST, that would mean the server which I assumed was in GMT is in fact in EST location. So, I need to change my account settings to EST then, to get consistent logs.&lt;BR /&gt;
I will try this and see if it helps in finding old logs in appropriate date time range.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 17:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447221#M95447</guid>
      <dc:creator>gsonal03</dc:creator>
      <dc:date>2019-03-16T17:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: What time is displayed in raw splunk logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447222#M95448</link>
      <description>&lt;P&gt;You've got it.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 17:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-time-is-displayed-in-raw-splunk-logs/m-p/447222#M95448</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-16T17:50:59Z</dc:date>
    </item>
  </channel>
</rss>

