Getting Data In

Problem with time in Edge Processor

adrifesa95
Engager

Hello,

I am receiving darktrace events through my Edge Processor as a Forwarder and I am a bit new to the SPL2 pipeline. It can probably be solved by transforming something in the pipeline.

The problem is that I am indexing events with a _time of -5h and a 2h difference from the event time stamp. Here is an example:

adrifesa95_1-1712747276840.png

 

Time in the Edge Processor:

adrifesa95_0-1712747181181.png

It should be noted that the rest of the events that I ingest through this server are arriving at the correct time.

Labels (2)
0 Karma

adrifesa95
Engager

Yes, but nothing relevant

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Look at the raw text rather than the JSON to see what Splunk may be using for timestamp detection. The JSON view is sorted and Splunk will only look a certain distance into the event to detect a timestamp (128 bytes by default).

If it cannot find a timestamp, then it will use current time

https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Propsconf#Timestamp_extraction_configuratio...

0 Karma

adrifesa95
Engager

Here the raw:
adrifesa95_0-1712821023278.png

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

That looks like it is more than 128 characters into the event, so you should set up MAX_TIMESTAMP_LOOKAHEAD and optionally TIME_PREFIX for your sourcetype for that data.

 

0 Karma

adrifesa95
Engager

How can I do this? Note that the forwarder is an Edge Processor and you can't touch the conf files, everything is modified in the GUI.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

OK, I'm unsure where the time will get extracted, but have you looked at this document

https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/EdgeProcessor/TimeExtractionPipeline

 

0 Karma

adrifesa95
Engager

yes...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...