<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk _time not matching with timestamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323475#M96546</link>
    <description>&lt;P&gt;It's really strange ...      &lt;CODE&gt;"time":"2018-01-21 05:42:34.0"&lt;/CODE&gt; &lt;BR /&gt;
There is only time field and all the events are of the same format...Some are taking the correct value and some are not even in the range or just picking up some random timestamp which is not even present in the event &lt;BR /&gt;
The data is being sent from S3 input from AWS addon &lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2018 20:21:38 GMT</pubDate>
    <dc:creator>nawazns5038</dc:creator>
    <dc:date>2018-01-23T20:21:38Z</dc:date>
    <item>
      <title>splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323472#M96543</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;the log has timestamp like this    &lt;CODE&gt;"time":"2018-01-22 13:43:40.0"&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;props.conf : &lt;BR /&gt;
TIME_FORMAT = %F %T.%3N&lt;BR /&gt;
TIME_PREFIX = "time":\"&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 25&lt;/P&gt;

&lt;P&gt;that was the props conf used. The setting worked fine while testing. After indexing the data the timestamp shown in Splunk or _time has come upto   &lt;CODE&gt;"11/28/17 4:06:53.568 PM"&lt;/CODE&gt; . which is even no where present in the event. &lt;/P&gt;

&lt;P&gt;How can this be resolved. Please help. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323472#M96543</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2020-09-29T17:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323473#M96544</link>
      <description>&lt;P&gt;Can you paste the full &lt;CODE&gt;_raw&lt;/CODE&gt; of the event in question?  Sometimes there are multiple instances of timestamps on one message, which can confuse Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 04:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323473#M96544</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-23T04:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323474#M96545</link>
      <description>&lt;P&gt;Hi nawazns5038, &lt;BR /&gt;
 Could you please provide sample events? Also in TIME_PREFIX try changing rex to &lt;CODE&gt;\"time\"\:\"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 04:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323474#M96545</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-01-23T04:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323475#M96546</link>
      <description>&lt;P&gt;It's really strange ...      &lt;CODE&gt;"time":"2018-01-21 05:42:34.0"&lt;/CODE&gt; &lt;BR /&gt;
There is only time field and all the events are of the same format...Some are taking the correct value and some are not even in the range or just picking up some random timestamp which is not even present in the event &lt;BR /&gt;
The data is being sent from S3 input from AWS addon &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 20:21:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323475#M96546</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-23T20:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323476#M96547</link>
      <description>&lt;P&gt;@p_gaurav &lt;/P&gt;

&lt;P&gt;There is only time field and all the events are of the same format...Some are taking the correct value and some are not even in the range or just picking up some random timestamp which is not even present in the event &lt;BR /&gt;
The data is being sent from S3 input from AWS addon &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 20:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323476#M96547</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-23T20:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323477#M96548</link>
      <description>&lt;P&gt;Are the events 'breaking' properly? Ie, one valid json block per event?&lt;BR /&gt;
Also is it aws generated data (s3/cloudwatch logs) etc, or your own log data?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 20:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323477#M96548</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-23T20:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323478#M96549</link>
      <description>&lt;P&gt;Ya breaking is proper and props has been tested with the sample data as well.  It is only one Json block. &lt;BR /&gt;
Data is pulled from S3 buckets and it is not AWS default data . and it is pulling lots of .gz files which has json files in it &lt;BR /&gt;
Is it a problem related to the Addon ? &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 23:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323478#M96549</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-23T23:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: splunk _time not matching with timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323479#M96550</link>
      <description>&lt;P&gt;Can you check _internal logs for particular S3 input? Is there any timestamp related warning or error? &lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 07:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-time-not-matching-with-timestamp/m-p/323479#M96550</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-01-24T07:07:14Z</dc:date>
    </item>
  </channel>
</rss>

