Getting Data In

Why is the event timestamp and the timestamp within my results different depending on the search?

karthi2809
Builder

My event timestamp and timestamp within my results are not same while i am searching in Splunk Web but some scenarios it's working fine. i attached the screen shots below.

Correct:
alt text

Wrong
alt text

Tags (1)
0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@karthi2809 - Did the answer provided by lguinn help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

lguinn2
Legend

The most likely answer is this: the log file is probably recording the data in the local time zone of the host. That is the time that you see in the body of the Event.
When the data is indexed into Splunk, the timestamp (the Time column in the screen shot) is converted to UTC and then stored with the original event data.
When you search, the timestamp is displayed, the Time column is displayed in the timezone that you have chosen as a user.

For some data, it is likely that your user timezone is the same as the original data, so it matches. For other data (hopefully collected from a server in a different timezone), it won't match. If this seems wrong to you, then you should confer with your Splunk Administrator to ensure that the timestamps/timezones are being extracted properly when the data is ingested into Splunk.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...