Getting Data In

Why is the event timestamp and the timestamp within my results different depending on the search?

karthi2809
Builder

My event timestamp and timestamp within my results are not same while i am searching in Splunk Web but some scenarios it's working fine. i attached the screen shots below.

Correct:
alt text

Wrong
alt text

Tags (1)
0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@karthi2809 - Did the answer provided by lguinn help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

lguinn2
Legend

The most likely answer is this: the log file is probably recording the data in the local time zone of the host. That is the time that you see in the body of the Event.
When the data is indexed into Splunk, the timestamp (the Time column in the screen shot) is converted to UTC and then stored with the original event data.
When you search, the timestamp is displayed, the Time column is displayed in the timezone that you have chosen as a user.

For some data, it is likely that your user timezone is the same as the original data, so it matches. For other data (hopefully collected from a server in a different timezone), it won't match. If this seems wrong to you, then you should confer with your Splunk Administrator to ensure that the timestamps/timezones are being extracted properly when the data is ingested into Splunk.

0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...