Getting Data In

Wrong timestamp Palo Alto

norbertt911
Communicator

Dear Splunkers,

Sorry about this, but I never did such thing before...

My Splunk is in EU and now I added PaloAlto firewall logs (collected by a Syslog and UF pushing them to Splunk) from AUS.

The timestamping is wrong.

First of all the today's events (11/06) are indexed on11th of Jun (06/11).  On the top, it is indexed two hours ahead than the current time.

now the events look like this :

11/06/2020
13:45:43.000
 
06-11-2020 21:45:43 User.Info 10.180.160.41 Nov 6 21:45:43 Firewall.device.name 1, ..........................................................

 

I'm using the Palo Alto add-on default for the source type, just the time zone changed to Sydney.  (Timestamp prefix : ^(?:[^,]*,){5}   ;   Lookahead 100)

Could you please advise what I should do? (what will happen if I  will have the same source type logs to the same index but from a different timezone? ) 

Regards,

Norbert

Labels (2)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @norbertt911 the props.conf setting on timestamp recognition got some issues. Can you copy paste your props/transforms here(after hiding the hostname values)

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

norbertt911
Communicator

Meanwhile, I found it 🙂

The Palo alto add-on permission was limited to the app, not Global. So if I search in Paloalto app it is ok, but that strange behavior in the default Search app.

Only the "bonus" question left. What will happen if I will have the same source type but from a different time zone? I should clone the original pan:log source type with a different time zone setting and add this new source type to props/transforms.conf?

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...