Getting Data In

Timestamp not being parsed correctly - Perfmon


Hi All,

I am collecting Perfmon data via the Splunk_TA_windows app and for some reason the time stamp is not being parsed correctly, specifically there is a delta between the Splunk assigned timestamp and the on in the event itself. e.g.:

alt text

Having looked through the internal logs I am not seeing anywhere that would indicate the queues are blocked, but I am still getting this discrepency. No modifications have been made to the TA , and it is has been installed on both the server that is sending the data, and the Indexer.

Any & all suggestions appreciated!

0 Karma


Add time zone to your time and this should be fixed

0 Karma


Unfortunately this won't help, as timezones differ (at a maximum) of 30 second increments. The delta above is ~2 minutes.

0 Karma

Super Champion

There is something wrong with your time. As of the time of your posting it was not 11/12/13 23:00 hours anywhere on the planet. Are you in space?
Are you seeing the same thing with other servers' forwarders?

Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...