All Apps and Add-ons

REST API Modular Input: Why is the timestamp on all my events 1 hour off and how do I fix this?

CSummersDOT
Explorer

Just installed the REST API Modular Input and love it so far, but I'm having 1 major issue. The timestamp on all of my events from this module are 1 hour ahead of my current time. Anything I can do to fix this? It's breaking the relative search in my dashboard.

0 Karma
1 Solution

CSummersDOT
Explorer

Found it. Pretty stupid of me, I didn't realize the json from the web api ad a datetime in it and it's 1 hour off.

View solution in original post

0 Karma

CSummersDOT
Explorer

Found it. Pretty stupid of me, I didn't realize the json from the web api ad a datetime in it and it's 1 hour off.

0 Karma

knutsod
Path Finder

You can tell splunk to use its own time for _time and not try and look it up in the event, but I would recommend just fixing the source if you can for accuracy.

knutsod
Path Finder

Are you referring to the _time field?

0 Karma

CSummersDOT
Explorer

Yes, _time. My other inputs are showing correct time but the REST and Command apps aren't. Couldn't find any reference to a TZ change in any prop.confs. No idea where to look now. Even read through the python script and all it does is return the json strong.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...