Getting Data In

timestamp and itime does not match

phamanh1652
Path Finder

We’re using Splunk Cloud and have configured SC4S to collect logs from FortiAnalyzer, which receives logs from both FortiGate and FortiWeb devices. Most events are processed correctly, with the timestamp and itime fields matching. However, we’ve noticed that for some events from FortiWeb, the timestamp is ahead of the itime by approximately 14–15 minutes. Based on our analysis, itime reflects the actual time the event occurred.

I’ve reviewed the raw logs and confirmed that all related components are configured to use the same time zone. Has anyone else experienced this issue? Any insights or solutions would be greatly appreciated.

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Btw, what do you mean by itime? Index time? How can it be ahead of the actual time?

0 Karma

phamanh1652
Path Finder

phamanh1652_1-1755240709055.png

This is an event of Fortiweb:

event time of splunk 11:53:13

timestamp=1755258793 ==> 11:53:13

itime=1755234267 ==> 12:04:27 ==> This is the actual time the event occurred.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

So it's actually the fortigate solution that is "lagging". If the main timestamp for the event should be the itime one, you need to change your props for that sourcetype to use that timestamp instead of the one at timestamp field

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Such offset (unless you're in a very very unusual time zone) suggests that either:

1) Time on the source is not set correctly or

2) There is an ingestion lag and (this is used as conjunction, not consequence) the timestamp is not parsed from the event itself but assigned from the time of ingestion.

0 Karma

PrewinThomas
Motivator

@phamanh1652 

Can you check system time on fortiweb? Is it configured locally or NTP?

#https://docs.fortinet.com/document/fortiweb/7.0.11/administration-guide/780143/setting-the-system-ti...


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

phamanh1652
Path Finder

Hello,

FortiWeb is configured with NTP.

Regards,

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...