Getting Data In

Wrong timestamp Palo Alto

norbertt911
Communicator

Dear Splunkers,

Sorry about this, but I never did such thing before...

My Splunk is in EU and now I added PaloAlto firewall logs (collected by a Syslog and UF pushing them to Splunk) from AUS.

The timestamping is wrong.

First of all the today's events (11/06) are indexed on11th of Jun (06/11).  On the top, it is indexed two hours ahead than the current time.

now the events look like this :

11/06/2020
13:45:43.000
 
06-11-2020 21:45:43 User.Info 10.180.160.41 Nov 6 21:45:43 Firewall.device.name 1, ..........................................................

 

I'm using the Palo Alto add-on default for the source type, just the time zone changed to Sydney.  (Timestamp prefix : ^(?:[^,]*,){5}   ;   Lookahead 100)

Could you please advise what I should do? (what will happen if I  will have the same source type logs to the same index but from a different timezone? ) 

Regards,

Norbert

Labels (2)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @norbertt911 the props.conf setting on timestamp recognition got some issues. Can you copy paste your props/transforms here(after hiding the hostname values)

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

norbertt911
Communicator

Meanwhile, I found it 🙂

The Palo alto add-on permission was limited to the app, not Global. So if I search in Paloalto app it is ok, but that strange behavior in the default Search app.

Only the "bonus" question left. What will happen if I will have the same source type but from a different time zone? I should clone the original pan:log source type with a different time zone setting and add this new source type to props/transforms.conf?

 

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...