<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Date latency in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505723#M4289</link>
    <description>It will "work" in that it will assign the current time to each event that arrives. It masks the latency problem. It makes old events look like new events and may throw off your reports.</description>
    <pubDate>Tue, 23 Jun 2020 12:29:18 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-06-23T12:29:18Z</dc:date>
    <item>
      <title>Date latency</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505234#M4262</link>
      <description>&lt;P&gt;I am receiving the logs from the forwarders and can see latency between index time and event time. We have difference between index time and event time is about 15 to 16 hours on more than 300 forwarders. How can&amp;nbsp; i fix this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 17:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505234#M4262</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2020-06-19T17:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Date latency</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505239#M4263</link>
      <description>&lt;P&gt;That's not (usually) a simple fix.&amp;nbsp; There are a variety of causes and finding the root cause will likely require intimate knowledge of your environment.&lt;/P&gt;&lt;P&gt;Some things to check include:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All servers are using NTP (or an equivalent time-sync service)&lt;/LI&gt;&lt;LI&gt;Time zones are set properly on each server&lt;/LI&gt;&lt;LI&gt;Event timestamps include a time zone indication or inputs.conf contains the &lt;FONT face="courier new,courier"&gt;TZ&lt;/FONT&gt; attribute&lt;/LI&gt;&lt;LI&gt;Props.conf has&amp;nbsp;&lt;FONT face="courier new,courier"&gt;TIME_FORMAT&lt;/FONT&gt; attributes that correctly extract the time zone from event timestamps&lt;/LI&gt;&lt;LI&gt;All Splunk forwarders are always running&lt;/LI&gt;&lt;LI&gt;Any intermediate servers or processes are always running&lt;/LI&gt;&lt;LI&gt;Events are not cached by the generating server/process before they are sent to Splunk&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 19 Jun 2020 18:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505239#M4263</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-19T18:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Date latency</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505653#M4288</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;Is DATETIME_CONFIG = CURRENT will work ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 05:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505653#M4288</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2020-06-23T05:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Date latency</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505723#M4289</link>
      <description>It will "work" in that it will assign the current time to each event that arrives. It masks the latency problem. It makes old events look like new events and may throw off your reports.</description>
      <pubDate>Tue, 23 Jun 2020 12:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505723#M4289</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-23T12:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Date latency</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505739#M4290</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Any other solution you can suggest to me. Because our thruput limit is set to 1024kb and that is fine . Any major issue we can fix this permanently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 13:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505739#M4290</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2020-06-23T13:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Date latency</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505743#M4291</link>
      <description>I offered 7 possible solutions in my first reply. Have you checked them?</description>
      <pubDate>Tue, 23 Jun 2020 13:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Date-latency/m-p/505743#M4291</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-23T13:41:24Z</dc:date>
    </item>
  </channel>
</rss>

