I am receiving the logs from the forwarders and can see latency between index time and event time. We have difference between index time and event time is about 15 to 16 hours on more than 300 forwarders. How can i fix this issue?
That's not (usually) a simple fix. There are a variety of causes and finding the root cause will likely require intimate knowledge of your environment.
Some things to check include:
@richgalloway Is DATETIME_CONFIG = CURRENT will work ?
@richgalloway Any other solution you can suggest to me. Because our thruput limit is set to 1024kb and that is fine . Any major issue we can fix this permanently.