Getting Data In

Timestamp not being parsed correctly - Perfmon

rturk
Builder

Hi All,

I am collecting Perfmon data via the Splunk_TA_windows app and for some reason the time stamp is not being parsed correctly, specifically there is a delta between the Splunk assigned timestamp and the on in the event itself. e.g.:

alt text

Having looked through the internal logs I am not seeing anywhere that would indicate the queues are blocked, but I am still getting this discrepency. No modifications have been made to the TA , and it is has been installed on both the server that is sending the data, and the Indexer.

Any & all suggestions appreciated!

0 Karma

royimad
Builder

Add time zone to your time and this should be fixed

0 Karma

rturk
Builder

Unfortunately this won't help, as timezones differ (at a maximum) of 30 second increments. The delta above is ~2 minutes.

0 Karma

lukejadamec
Super Champion

There is something wrong with your time. As of the time of your posting it was not 11/12/13 23:00 hours anywhere on the planet. Are you in space?
Are you seeing the same thing with other servers' forwarders?

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...