Dashboards & Visualizations

Question about accuracy of results when specifying the time range

johnblakley
Explorer

What would cause times to be off on received logs? I installed the UF on a server yesterday that had the correct time. If I search for "All Time" for that host, I receive log entries for 8/1/2018, but if I specify ANY time range - last 7 days, last 24 hours, etc., it shows the correct time. Is this a bug in Splunk?

alt text

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

The date is exactly what appears to be in the event data 08/01/2018 10:45:51 PM. so it is just using the date in the event for the timestamp. This is perfectly logical and valid for Splunk to do. You certainly can have future dates in your data, if that is the date that is considered valid in the event (or not, if it is just using the wrong date from the event data).

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...