Getting Data In

How to fix time for the Index, Source and Timeline graph so they the same?

kwaingrow
Path Finder

Set up: The system clocks for our Searcher and Indexers run GMT, our events are coming from servers posting in PST, EST and GMT.

I have 2 questions/Issues:
1) The index, Source, and timeline display time are all different and out of sync. How can I get them in sync? (see picture: http://www.ugu.com/splunk/time.jpg)

2) One indexer displays the Index time in GMT and all of our other indexers display the index time the same as the event source time. What would make this one indexer different from the rest.

1 Solution

kwaingrow
Path Finder

Resolved: Restart of Splunk Searcher resolved the issue.

View solution in original post

0 Karma

kwaingrow
Path Finder

Resolved: Restart of Splunk Searcher resolved the issue.

0 Karma

kwaingrow
Path Finder

ooops, Sorry. Version 4.2.3-105575

Also #2 has been resolved after a reboot of the server had been preformed.

But #1 display time on the top graph is not the same as the indexed time or the source time. Could this be a bug in the version we are running? http://www.ugu.com/splunk/time.jpg

0 Karma

piebob
Splunk Employee
Splunk Employee

what version of Splunk are you running?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...