Knowledge Management

Why is the timestamp showing up in the future on some sourcetypes for few servers?

AK_Splunk
Explorer

I am facing issue for certain sourcetype the indexed events are with the future time stamp. The data of these source type is getting indexed in splunk via HF and forwarded to IDX. The props is defined from the SH GUI. please help me understand and eradicate this issue.

Example

event data
12/12/2024 10:08:24 PM
LogName=Application
SourceName=Galaxy
EventCode=1
EventType=4
Type=Information
ComputerName=testserver.gtest.com

TaskCategory=None
OpCode=None
RecordNumber=8425512
Keywords=Classic

0 Karma

shivanshu1593
Builder

Unable to understand the requirement here. Your sample event contains the date of December 2024, which would obviously make Splunk create a bucket for a future timestamp and store it there. Could you please elaborate your requirement a bit so that we can propose a solution for you.

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

AK_Splunk
Explorer

Thanks for your response.
The data I showed is event data which is the time stamp of 2024 and the time should be showing as today's date and time.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...