<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time Stamp Help! in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696321#M236664</link>
    <description>&lt;P&gt;There seems to be probably TZ issue with some other issues with your ingestion phase. If I recall right TZ are +/- 1h or x.5h difference with local time and UTC time. But your time difference didn’t match that.&lt;/P&gt;&lt;P&gt;You must get your correct props.conf and also raw source event before it was ingested into splunk. With those we could help you.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2024 21:17:20 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-08-14T21:17:20Z</dc:date>
    <item>
      <title>Time Stamp Help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696307#M236657</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello, I have time stamps that are not matching. How do I table the actual "Event log time stamp" ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="866"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="142.926px" height="46px"&gt;Splunk Time stamp&lt;/TD&gt;&lt;TD width="722.159px" height="46px"&gt;Event log time stamp&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="142.926px" height="61px"&gt;&lt;SPAN&gt;8/14/24&lt;BR /&gt;4:29:21.000 AM&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="722.159px" height="61px"&gt;&lt;P&gt;&lt;BR /&gt;2024-08-13 17:49:23,006 [https-mmme-nio-1111-exec-2] ERROR&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696307#M236657</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2024-08-14T19:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp Help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696310#M236659</link>
      <description>&lt;P&gt;What you have on raw event and how you have define timestamp extraction on props.conf?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:49:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696310#M236659</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-08-14T19:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp Help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696315#M236661</link>
      <description>&lt;P&gt;Hi&amp;nbsp; @&lt;SPAN&gt;isoutamo,&amp;nbsp;&lt;/SPAN&gt; The below is the raw event. I dont have access to props.conf. so just wanted to extract the time stamp from the raw event.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2024-08-13 17:49:23,006 [https-mmme-nio-1111-exec-2] ERROR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 20:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696315#M236661</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2024-08-14T20:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp Help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696317#M236662</link>
      <description>&lt;P&gt;I indexed this log in a new sourcetype on a test machine in the GMT+2 timezone, and the timestamp seems to have extracted properly. We would need to know what your timestamp settings in props.conf are to find out where the timestamp extraction is going wrong.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marnall_0-1723667418941.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32218i4CAB5285064993D6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="marnall_0-1723667418941.png" alt="marnall_0-1723667418941.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 20:31:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696317#M236662</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-08-14T20:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp Help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696321#M236664</link>
      <description>&lt;P&gt;There seems to be probably TZ issue with some other issues with your ingestion phase. If I recall right TZ are +/- 1h or x.5h difference with local time and UTC time. But your time difference didn’t match that.&lt;/P&gt;&lt;P&gt;You must get your correct props.conf and also raw source event before it was ingested into splunk. With those we could help you.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 21:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696321#M236664</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-08-14T21:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Time Stamp Help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696347#M236671</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Hi&amp;nbsp; @&lt;SPAN&gt;isoutamo,&amp;nbsp;&lt;/SPAN&gt; The below is the raw event. I dont have access to props.conf. so just wanted to extract&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;You do not need direct access to props.conf. &amp;nbsp;Just use Splunk Web's Settings -&amp;gt; Source Types interface. &amp;nbsp;There are two menus where you can customize your timestamp handling, Timestamp and Advanced.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sourcetype-timestamp.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32224i4C506A323ABAB551/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sourcetype-timestamp.png" alt="sourcetype-timestamp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sourcetype-advanced.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32225i539ED80FBB5ECD65/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sourcetype-advanced.png" alt="sourcetype-advanced.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;says, your problem might not be in Splunk's time extraction; instead, the apparent difference could be in time zone. &amp;nbsp;If this is not the case, the best cause of action is to correct time extraction. &amp;nbsp;Search time correction should only be used as the last resort. &amp;nbsp;It can be done, of course.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "^(?&amp;lt;timestamp&amp;gt;\S+ \S+)"
| eval _time = strptime(timestamp, "%F %T,%3N")&lt;/LI-CODE&gt;&lt;P&gt;The big problem with search time adjustment of an essential datapoint such as _time is that you lose precision when trying to set index search interval.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 06:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-Stamp-Help/m-p/696347#M236671</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-15T06:00:47Z</dc:date>
    </item>
  </channel>
</rss>

