Getting Data In

How to time warp from a certain IP?

danielbb
Motivator

We have a case where -

 

index = network_index host=xx.xx.xx.xx
| eval lag_sec = (_indextime - _time)
| stats count by lag_sec

 

_time is current but _indextime is 37 minute earlier. 

What can it be? 

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

If _indextime is earlier than _time it most probably means some misconfiguration in the timezone department. And optionally - if the difference is not in full hours - lack of time sync, choking on reporting somewhere or a source which reads batches of events periodicaly.

But most probably there is some inconsistency between what source thinks it sends as timestamp and how splunk interprets it.

Check the raw data and look at the timestamps.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...