Getting Data In

timestamp and itime does not match

phamanh1652
Path Finder

We’re using Splunk Cloud and have configured SC4S to collect logs from FortiAnalyzer, which receives logs from both FortiGate and FortiWeb devices. Most events are processed correctly, with the timestamp and itime fields matching. However, we’ve noticed that for some events from FortiWeb, the timestamp is ahead of the itime by approximately 14–15 minutes. Based on our analysis, itime reflects the actual time the event occurred.

I’ve reviewed the raw logs and confirmed that all related components are configured to use the same time zone. Has anyone else experienced this issue? Any insights or solutions would be greatly appreciated.

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Btw, what do you mean by itime? Index time? How can it be ahead of the actual time?

0 Karma

phamanh1652
Path Finder

phamanh1652_1-1755240709055.png

This is an event of Fortiweb:

event time of splunk 11:53:13

timestamp=1755258793 ==> 11:53:13

itime=1755234267 ==> 12:04:27 ==> This is the actual time the event occurred.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

So it's actually the fortigate solution that is "lagging". If the main timestamp for the event should be the itime one, you need to change your props for that sourcetype to use that timestamp instead of the one at timestamp field

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Such offset (unless you're in a very very unusual time zone) suggests that either:

1) Time on the source is not set correctly or

2) There is an ingestion lag and (this is used as conjunction, not consequence) the timestamp is not parsed from the event itself but assigned from the time of ingestion.

0 Karma

PrewinThomas
Motivator

@phamanh1652 

Can you check system time on fortiweb? Is it configured locally or NTP?

#https://docs.fortinet.com/document/fortiweb/7.0.11/administration-guide/780143/setting-the-system-ti...


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

phamanh1652
Path Finder

Hello,

FortiWeb is configured with NTP.

Regards,

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...