Getting Data In

Indexed time and event logged time is mismatching

gkumarashanmuga
Explorer

We are getting events from one of our application ,But the indexed time and event logged time is different ,Please let me know how to fix this timestamp issues. I guess need to use props.conf timestamp settings.

Sample event :

I viewed it in list mode

Time
6/6/18
11:28:09.000 AM

EVENT
20 6 Jun 6 11:28:09 hostname TAG: Hostd: info hostd [abcd@111] Test Backup succeeded

Likewise all the events are generated

If i viewed in Raw mode :

20 6 Jun 6 11:28:09 hostname TAG: Hostd: info hostd [abcd@11] Test Backup succeeded.

0 Karma

DEAD_BEEF
Builder

I don't see anything wrong with the time either. It may help if you included a screenshot or something. Both timestamps are 11:28:09. What's the issue?

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'm not sure I see what's wrong. I see no year in your raw event, so from where would Splunk get a value to use other than "The current year?"

Unless - is the "20 6" supposed to be "2006" or "2016" or "2026" or something?

Do you have any control over the format of the raw events?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...