Getting Data In

Best practice for Splunk to index syslog events with correct time?

rune_hellem
Contributor

Splunk 8.0.4

Indexing syslog events from the Symantec Blue Coat ProxySG. Using the app https://docs.splunk.com/Documentation/AddOns/released/BlueCoatProxySG/About to set the correct souretype. 

Example event

 

 

2020-06-11 12:01:42 34 172.21.207.129 dkkguest - 123.160.120.251 123.160.120.251 Unavailable - - OBSERVED "News" -  200 TCP_HIT GET text/xml;%20charset=utf-8 http weather.service.msn.com 80 /data.aspx ?wealocations=wc%3aNOXX0001&culture=nb-NO&weadegreetype=C&src=outlook aspx "Mozilla/4.0 (compatible; ms-office; MSOffice 16)" 172.20.170.129 1099 294 - "none" "none" "none" unavailable 4f09400d3d550882-0000000102455180-000000005ee21d26 - -

 

 

The time of the event 12:01 is indexed by Splunk as 12:01 as well, but it should be two hours later - 14:01. I would expect Splunk to handle this out of the box, but it won't. 

Setting this on the sourcetype for instance would not be a good idea, for what if another applicance comes along with different time settings? 

So how do I best approach this?

Labels (1)
0 Karma

to4kawa
Ultra Champion

What is the time zone of the log and what is your time zone?

The log time is in the local time zone by default.

0 Karma

rune_hellem
Contributor

As you see from the sample event, there are no timezone-info in the event itself. Splunk timezone is CES (Summer time) for the moment. My first guess would be that the Bluecoat is UTC, but that is just -1 hour from CES, it is -2. 

The log time shown in the event example is the same as the time shown in the console of the Bluecoat device (I will get the admin to verify one more time).

I guess that we could manage to change the time on the Bluecoat device, but as mentioned - should that really be needed? Could maybe see if we are able to customize the syslog event so that the timestamp has timezone info as well. 

0 Karma

to4kawa
Ultra Champion

https://www.timeanddate.com/time/zones/cet

https://www.timeanddate.com/time/zones/cest

It's not even summer time,I guess.

https://docs.splunk.com/Documentation/Splunk/8.0.4/Search/Abouttimezones

 

The easy way is to change the time zone in the user Account Settings.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...