Getting Data In

Why is the event timestamp and the timestamp within my results different depending on the search?

karthi2809
Builder

My event timestamp and timestamp within my results are not same while i am searching in Splunk Web but some scenarios it's working fine. i attached the screen shots below.

Correct:
alt text

Wrong
alt text

Tags (1)
0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@karthi2809 - Did the answer provided by lguinn help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

lguinn2
Legend

The most likely answer is this: the log file is probably recording the data in the local time zone of the host. That is the time that you see in the body of the Event.
When the data is indexed into Splunk, the timestamp (the Time column in the screen shot) is converted to UTC and then stored with the original event data.
When you search, the timestamp is displayed, the Time column is displayed in the timezone that you have chosen as a user.

For some data, it is likely that your user timezone is the same as the original data, so it matches. For other data (hopefully collected from a server in a different timezone), it won't match. If this seems wrong to you, then you should confer with your Splunk Administrator to ensure that the timestamps/timezones are being extracted properly when the data is ingested into Splunk.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...