Splunk Cloud Platform

Question on matching event time and index time

dannyze
Explorer

Hi all,
I am pulling events in alerts and seeing a gap between _time and _indextime. Around 535 seconds average difference. I have 2 questions
1) What is the best practice approach to match these field values to each other? So have the results of 

 

_time = _indextime 

 


2) Is this time delay a sign of other things to investigate in the pipeline? 
 Per this post https://community.splunk.com/t5/Getting-Data-In/Time-difference-practical-values-between-event-time-...
this is a rather significant time difference. 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Here are a few things to check:

  1. Make sure all systems are running NTP (or equivalent)
  2. Verify time zones are set correctly on all systems.
  3. Check the indexer pipelines queues for backlogs.
  4. Verify the storage system is providing the expected IOPS.
  5. Check for any intermediate servers (proxy, forwarder, etc) that may be slowing things down.
  6. Make sure the data source is not caching events before releasing them to Splunk.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...