Getting Data In

While searching DHCP logs there are huge latency (indextime -time) for few events

pavanbmishra
Path Finder

Hi SMEs, i have quick query here. While searching DHCP logs i could see huge latency (indextime -time) for few events , rest all looks ok. sharing two consecutive event logs with minimal and max latency reported. Any clue. Event collection is through UF here

latency issue.PNG

Labels (1)
Tags (1)
0 Karma

pavanbmishra
Path Finder

Ok, and how that could be checked/confirmed? however these both logs from same host here.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

One entry says date_zone 0 and the other says date_zone local - where do these come from? Presumably, this is something from the DHCP server itself. Do you have any documentation on the DHCP server logging process?

Alternatively, can you use this field to adjust your calculation of what the "latency" might be?

ITWhisperer
SplunkTrust
SplunkTrust

Could it be that one entry has a timestamp in local time (UTC-05:00 approx.) whereas the other is in 0 time?

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...