Getting Data In

Different timestamp recognition for same stanza

bfernandez
Communicator

I am gathering perfmon data from two windows servers but Splunk 5.0 no correctly recognize the timestamp in one of them.

[perfmon://LocalPhysicalDisk]
counters = % Free Space;Free Megabytes
interval = 60
object = LogicalDisk
disabled = 0

Wrong timestamp data is generated on a cloud server with a different time that our network although we are both using the default Microsoft ntp server.

Splunk Timestamp Data Timestamp
11/22/12 9:53:49.765 PM 11/22/2012 21:53:49.765 (local sever)
11/22/12 10:05:38.000 PM 11/22/2012 22:06:21.062 (cloud server)

Why Splunk doesn’t simply use the timestamp of the data?

Thanks!!

bfernandez
Communicator

I am using the default value /etc/datetime.xml to recognise the timestamp in data

sowings
Splunk Employee
Splunk Employee

Do you have DATETIME_CONFIG = CURRENT in your props.conf?

0 Karma

gfuente
Motivator

Hello Borja

You should set up correctly the time configuration from windows time to syncronize with a central time server

Reagrds

bfernandez
Communicator

All the servers have the same TZ, but not the same time, so in this case splunk should use the server's TZ.

I reckon that the problem is other but I will try setting this option in props.conf.

Thanks.

lguinn2
Legend

Splunk may be trying to consider the timezone of each server. This might be found in the event - or it could be set in props.conf for cloud server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...