Getting Data In

While searching DHCP logs there are huge latency (indextime -time) for few events

pavanbmishra
Path Finder

Hi SMEs, i have quick query here. While searching DHCP logs i could see huge latency (indextime -time) for few events , rest all looks ok. sharing two consecutive event logs with minimal and max latency reported. Any clue. Event collection is through UF here

latency issue.PNG

Labels (1)
Tags (1)
0 Karma

pavanbmishra
Path Finder

Ok, and how that could be checked/confirmed? however these both logs from same host here.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

One entry says date_zone 0 and the other says date_zone local - where do these come from? Presumably, this is something from the DHCP server itself. Do you have any documentation on the DHCP server logging process?

Alternatively, can you use this field to adjust your calculation of what the "latency" might be?

ITWhisperer
SplunkTrust
SplunkTrust

Could it be that one entry has a timestamp in local time (UTC-05:00 approx.) whereas the other is in 0 time?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...