Getting Data In

While searching DHCP logs there are huge latency (indextime -time) for few events

pavanbmishra
Path Finder

Hi SMEs, i have quick query here. While searching DHCP logs i could see huge latency (indextime -time) for few events , rest all looks ok. sharing two consecutive event logs with minimal and max latency reported. Any clue. Event collection is through UF here

latency issue.PNG

Labels (1)
Tags (1)
0 Karma

pavanbmishra
Path Finder

Ok, and how that could be checked/confirmed? however these both logs from same host here.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

One entry says date_zone 0 and the other says date_zone local - where do these come from? Presumably, this is something from the DHCP server itself. Do you have any documentation on the DHCP server logging process?

Alternatively, can you use this field to adjust your calculation of what the "latency" might be?

ITWhisperer
SplunkTrust
SplunkTrust

Could it be that one entry has a timestamp in local time (UTC-05:00 approx.) whereas the other is in 0 time?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...