<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Delay in logs from Incapsula to S3 Bucket in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Delay-in-logs-from-Incapsula-to-S3-Bucket/m-p/392056#M95641</link>
    <description>&lt;P&gt;Morning Guys,&lt;/P&gt;

&lt;P&gt;We are currently having an issue with our Incapsula WAF sending logs to our AWS s3 Bucket with a delay and hoping to use a query within Splunk to provide evidence of these delays.&lt;/P&gt;

&lt;P&gt;So far I have got as far as the following:&lt;/P&gt;

&lt;P&gt;index=incapsula | eval delay_sec=_indextime-_time | convert ctime(_indextime) AS indextime | eval now=now() | table _time indextime now date_zone source sourcetype host&lt;/P&gt;

&lt;P&gt;This gives a table similar to what I am after, however Im looking for the actual time stamps (epoch) on the events as they happened and the actual time the  log file arrived in the s3 bucket rather than the time the log file arrived at the index, any thoughts on how to modify this query to get the necessary information at all?&lt;/P&gt;

&lt;P&gt;Cheers guys&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:18:34 GMT</pubDate>
    <dc:creator>brewster88</dc:creator>
    <dc:date>2020-09-29T23:18:34Z</dc:date>
    <item>
      <title>Delay in logs from Incapsula to S3 Bucket</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Delay-in-logs-from-Incapsula-to-S3-Bucket/m-p/392056#M95641</link>
      <description>&lt;P&gt;Morning Guys,&lt;/P&gt;

&lt;P&gt;We are currently having an issue with our Incapsula WAF sending logs to our AWS s3 Bucket with a delay and hoping to use a query within Splunk to provide evidence of these delays.&lt;/P&gt;

&lt;P&gt;So far I have got as far as the following:&lt;/P&gt;

&lt;P&gt;index=incapsula | eval delay_sec=_indextime-_time | convert ctime(_indextime) AS indextime | eval now=now() | table _time indextime now date_zone source sourcetype host&lt;/P&gt;

&lt;P&gt;This gives a table similar to what I am after, however Im looking for the actual time stamps (epoch) on the events as they happened and the actual time the  log file arrived in the s3 bucket rather than the time the log file arrived at the index, any thoughts on how to modify this query to get the necessary information at all?&lt;/P&gt;

&lt;P&gt;Cheers guys&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Delay-in-logs-from-Incapsula-to-S3-Bucket/m-p/392056#M95641</guid>
      <dc:creator>brewster88</dc:creator>
      <dc:date>2020-09-29T23:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Delay in logs from Incapsula to S3 Bucket</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Delay-in-logs-from-Incapsula-to-S3-Bucket/m-p/392057#M95642</link>
      <description>&lt;P&gt;This is not possible.  You will have to build some other process in AWS to add more data and then send that to Splunk, too, and correlate it.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:43:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Delay-in-logs-from-Incapsula-to-S3-Bucket/m-p/392057#M95642</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-06T08:43:56Z</dc:date>
    </item>
  </channel>
</rss>

