Getting Data In

While searching DHCP logs there are huge latency (indextime -time) for few events

pavanbmishra
Path Finder

Hi SMEs, i have quick query here. While searching DHCP logs i could see huge latency (indextime -time) for few events , rest all looks ok. sharing two consecutive event logs with minimal and max latency reported. Any clue. Event collection is through UF here

latency issue.PNG

Labels (1)
Tags (1)
0 Karma

pavanbmishra
Path Finder

Ok, and how that could be checked/confirmed? however these both logs from same host here.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

One entry says date_zone 0 and the other says date_zone local - where do these come from? Presumably, this is something from the DHCP server itself. Do you have any documentation on the DHCP server logging process?

Alternatively, can you use this field to adjust your calculation of what the "latency" might be?

ITWhisperer
SplunkTrust
SplunkTrust

Could it be that one entry has a timestamp in local time (UTC-05:00 approx.) whereas the other is in 0 time?

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...