Getting Data In

While searching DHCP logs there are huge latency (indextime -time) for few events

pavanbmishra
Path Finder

Hi SMEs, i have quick query here. While searching DHCP logs i could see huge latency (indextime -time) for few events , rest all looks ok. sharing two consecutive event logs with minimal and max latency reported. Any clue. Event collection is through UF here

latency issue.PNG

Labels (1)
Tags (1)
0 Karma

pavanbmishra
Path Finder

Ok, and how that could be checked/confirmed? however these both logs from same host here.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

One entry says date_zone 0 and the other says date_zone local - where do these come from? Presumably, this is something from the DHCP server itself. Do you have any documentation on the DHCP server logging process?

Alternatively, can you use this field to adjust your calculation of what the "latency" might be?

ITWhisperer
SplunkTrust
SplunkTrust

Could it be that one entry has a timestamp in local time (UTC-05:00 approx.) whereas the other is in 0 time?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...