All Apps and Add-ons

Solarwinds Alerts Timestamp issue

brandonf
Path Finder

Howdy

We have installed and configured the add-on and data is being retrieved. However we notice that the timestamp on the alert events is wrong - it seems to be exactly 2 hours behind. We check the SQL eventtime and it is correct there but the script seems to to be incorrectly interpreting the timestamp?

The format in the database is YYYY-mm-dd HH:MM:SS.3N but Splunk shows YYYY-mm-ddTHH:MM:SS.XXXXXX

Thanks
B

0 Karma

ankurpwc
Engager

HI brandonf,

Have you found solution for this ? we too are facing exactly same issue.

0 Karma

neltavares
New Member

We are noticing the exact same behavior as described above, but in our case we are exactly 5 hours behind, which coincides with the difference between our time zone (Eastern Standard) and UTC time.

Solarwinds is forwarding events to splunk correctly, but the events are from exactly 5 hours ago.
So an alert sent from solarwinds to splunk with the following eventTime: EventTime: 2018-12-18T15:39:16.2600000 actually appeared in solarwinds at 10:39 (and not 15:39).

Has anyone found a way to correct this?

Thanks!

0 Karma

macadminrohit
Contributor

We had similar problem but not in solarwinds app. for this sourcetype you can specifically define TIME_PREFIX and TIME_FORMAT in props.conf since you dont have TZ in the event itself . You can set TZ in props.conf and explicitly let Splunk know which TZ event is in .

See the below link, this should help you.

https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Applytimezoneoffsetstotimestamps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...