Getting Data In

Best practice for Splunk to index syslog events with correct time?

rune_hellem
Contributor

Splunk 8.0.4

Indexing syslog events from the Symantec Blue Coat ProxySG. Using the app https://docs.splunk.com/Documentation/AddOns/released/BlueCoatProxySG/About to set the correct souretype. 

Example event

 

 

2020-06-11 12:01:42 34 172.21.207.129 dkkguest - 123.160.120.251 123.160.120.251 Unavailable - - OBSERVED "News" -  200 TCP_HIT GET text/xml;%20charset=utf-8 http weather.service.msn.com 80 /data.aspx ?wealocations=wc%3aNOXX0001&culture=nb-NO&weadegreetype=C&src=outlook aspx "Mozilla/4.0 (compatible; ms-office; MSOffice 16)" 172.20.170.129 1099 294 - "none" "none" "none" unavailable 4f09400d3d550882-0000000102455180-000000005ee21d26 - -

 

 

The time of the event 12:01 is indexed by Splunk as 12:01 as well, but it should be two hours later - 14:01. I would expect Splunk to handle this out of the box, but it won't. 

Setting this on the sourcetype for instance would not be a good idea, for what if another applicance comes along with different time settings? 

So how do I best approach this?

Labels (1)
0 Karma

to4kawa
Ultra Champion

What is the time zone of the log and what is your time zone?

The log time is in the local time zone by default.

0 Karma

rune_hellem
Contributor

As you see from the sample event, there are no timezone-info in the event itself. Splunk timezone is CES (Summer time) for the moment. My first guess would be that the Bluecoat is UTC, but that is just -1 hour from CES, it is -2. 

The log time shown in the event example is the same as the time shown in the console of the Bluecoat device (I will get the admin to verify one more time).

I guess that we could manage to change the time on the Bluecoat device, but as mentioned - should that really be needed? Could maybe see if we are able to customize the syslog event so that the timestamp has timezone info as well. 

0 Karma

to4kawa
Ultra Champion

https://www.timeanddate.com/time/zones/cet

https://www.timeanddate.com/time/zones/cest

It's not even summer time,I guess.

https://docs.splunk.com/Documentation/Splunk/8.0.4/Search/Abouttimezones

 

The easy way is to change the time zone in the user Account Settings.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...