Getting Data In

Why are there discrepancies between native UTC time of the event and Splunk's processed time?

Thuan
Explorer

The 2 lines below show (line 1) the time processed by a Splunk indexer on EST time. The 2nd line starts with the corresponding timestamp of a native syslog record. The 2nd time stamp says that it is UTC-based with an offset of 4 hours. And yet the difference between the two stamps is 8 hours.

3/30/15 2:34:38.000 AM  
2015-03-30T10:34:38-04:00 147.81.86.22 %ASA-6-302015: Built outbound UDP connection 785924 for outside:DNS1.ENGILITYCORP.COM/53 (DNS1.ENGILITYCORP.COM/53) to inside:TSEADC01/63217 (TSEADC01/63217)

In props.conf, the time format used is:

TIME_FORMAT = %Y-%m-%dT%H:%M:%S-%z

Where is the error?

Thank you.

0 Karma
1 Solution

acharlieh
Influencer

I'm not sure if this is it, as I haven't looked deeply enough to do the math but I think your format should be

TIME_FORMAT = %Y-%m-%dT%H:%M:%S%z

since the - is part of the timezone specification (UTC-04:00 versus UTC+04:00)

View solution in original post

acharlieh
Influencer

I'm not sure if this is it, as I haven't looked deeply enough to do the math but I think your format should be

TIME_FORMAT = %Y-%m-%dT%H:%M:%S%z

since the - is part of the timezone specification (UTC-04:00 versus UTC+04:00)

Thuan
Explorer

It works. Thank you. The :z: spec to include the - is indeed the correct format.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...