Splunk Cloud Platform

On certain events the indexed time is 24h after the event _time across all indexes on Splunk cloud

joe06031990
Communicator

Hi,

 

On certain events the indexed time is 24h after the event _time across all indexes on Splunk cloud, just wondered if anyone has seen this before it doesn’t look to matter on the source type that is used.

 

 

thanks,

 

Tags (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

If the _indextime is 24h after the event _time, are the events just coming in 24 later from the host that is sending the events?

Is there any consistency between any of the events that are late? host/index/source/sourcetype?

It is always an exact 24h difference to the event _time?

Are these events coming in from a universal forwarder, HEC, through a heavy forwarder?

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

If the _indextime is 24h after the event _time, are the events just coming in 24 later from the host that is sending the events?

Is there any consistency between any of the events that are late? host/index/source/sourcetype?

It is always an exact 24h difference to the event _time?

Are these events coming in from a universal forwarder, HEC, through a heavy forwarder?

 

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...