Getting Data In

Timestamp not being parsed correctly - Perfmon

rturk
Builder

Hi All,

I am collecting Perfmon data via the Splunk_TA_windows app and for some reason the time stamp is not being parsed correctly, specifically there is a delta between the Splunk assigned timestamp and the on in the event itself. e.g.:

alt text

Having looked through the internal logs I am not seeing anywhere that would indicate the queues are blocked, but I am still getting this discrepency. No modifications have been made to the TA , and it is has been installed on both the server that is sending the data, and the Indexer.

Any & all suggestions appreciated!

0 Karma

royimad
Builder

Add time zone to your time and this should be fixed

0 Karma

rturk
Builder

Unfortunately this won't help, as timezones differ (at a maximum) of 30 second increments. The delta above is ~2 minutes.

0 Karma

lukejadamec
Super Champion

There is something wrong with your time. As of the time of your posting it was not 11/12/13 23:00 hours anywhere on the planet. Are you in space?
Are you seeing the same thing with other servers' forwarders?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...