All Apps and Add-ons

REST API Modular Input: Why is the timestamp on all my events 1 hour off and how do I fix this?

CSummersDOT
Explorer

Just installed the REST API Modular Input and love it so far, but I'm having 1 major issue. The timestamp on all of my events from this module are 1 hour ahead of my current time. Anything I can do to fix this? It's breaking the relative search in my dashboard.

0 Karma
1 Solution

CSummersDOT
Explorer

Found it. Pretty stupid of me, I didn't realize the json from the web api ad a datetime in it and it's 1 hour off.

View solution in original post

0 Karma

CSummersDOT
Explorer

Found it. Pretty stupid of me, I didn't realize the json from the web api ad a datetime in it and it's 1 hour off.

0 Karma

knutsod
Path Finder

You can tell splunk to use its own time for _time and not try and look it up in the event, but I would recommend just fixing the source if you can for accuracy.

knutsod
Path Finder

Are you referring to the _time field?

0 Karma

CSummersDOT
Explorer

Yes, _time. My other inputs are showing correct time but the REST and Command apps aren't. Couldn't find any reference to a TZ change in any prop.confs. No idea where to look now. Even read through the python script and all it does is return the json strong.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...