Getting Data In

How to time warp from a certain IP?


We have a case where -


index = network_index host=xx.xx.xx.xx
| eval lag_sec = (_indextime - _time)
| stats count by lag_sec


_time is current but _indextime is 37 minute earlier. 

What can it be? 

Labels (1)
Tags (1)
0 Karma

Ultra Champion

If _indextime is earlier than _time it most probably means some misconfiguration in the timezone department. And optionally - if the difference is not in full hours - lack of time sync, choking on reporting somewhere or a source which reads batches of events periodicaly.

But most probably there is some inconsistency between what source thinks it sends as timestamp and how splunk interprets it.

Check the raw data and look at the timestamps.

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...