Dashboards & Visualizations

Question about accuracy of results when specifying the time range

johnblakley
Explorer

What would cause times to be off on received logs? I installed the UF on a server yesterday that had the correct time. If I search for "All Time" for that host, I receive log entries for 8/1/2018, but if I specify ANY time range - last 7 days, last 24 hours, etc., it shows the correct time. Is this a bug in Splunk?

alt text

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

The date is exactly what appears to be in the event data 08/01/2018 10:45:51 PM. so it is just using the date in the event for the timestamp. This is perfectly logical and valid for Splunk to do. You certainly can have future dates in your data, if that is the date that is considered valid in the event (or not, if it is just using the wrong date from the event data).

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...