Splunk Cloud Platform

Question on matching event time and index time

dannyze
Explorer

Hi all,
I am pulling events in alerts and seeing a gap between _time and _indextime. Around 535 seconds average difference. I have 2 questions
1) What is the best practice approach to match these field values to each other? So have the results of 

 

_time = _indextime 

 


2) Is this time delay a sign of other things to investigate in the pipeline? 
 Per this post https://community.splunk.com/t5/Getting-Data-In/Time-difference-practical-values-between-event-time-...
this is a rather significant time difference. 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Here are a few things to check:

  1. Make sure all systems are running NTP (or equivalent)
  2. Verify time zones are set correctly on all systems.
  3. Check the indexer pipelines queues for backlogs.
  4. Verify the storage system is providing the expected IOPS.
  5. Check for any intermediate servers (proxy, forwarder, etc) that may be slowing things down.
  6. Make sure the data source is not caching events before releasing them to Splunk.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...