Splunk Enterprise

Correcting ingesting timestamp for Solarwinds alert

tstewart
Explorer

Hello,

I recently enabled a SolarWinds alert in the inputs.conf on the heavy forwarder. The data is now ingesting into Splunk, but the timestamps are appearing in UTC instead of local time. The interval is set to 899. All other SolarWinds alerts ingesting into Splunk are showing the correct local time, so this issue seems isolated to the newly enabled alert. Any guidance on what might cause this specific alert to default to UTC—whether related to the alert configuration, timestamp parsing, or a missing props/transforms setting—would be appreciated.

 
Labels (1)
0 Karma
1 Solution

tstewart
Explorer
Thank you! Adding the TIME_PREFIX and TIME_FORMAT fixed the issue. I also added the MAX_TIMESTAMP_LOOKAHEAD and TZ as well.

View solution in original post

inventsekar
SplunkTrust
SplunkTrust

for current and future learners reference, i would like to post the Splunk's "Magic 8"

https://kinneygroup.com/blog/splunk-magic-8-props-conf/

 

PickleRick
SplunkTrust
SplunkTrust

Apart from all the things already mentioned by @richgalloway , check the contents of the event itself and compare to the other - "working" - events. Do the timestamps in those alert contain timestamps in the same timezone? Are they formatted the same way? Are they even extracted and used properly by Splunk or is the ingestion time used instead?

richgalloway
SplunkTrust
SplunkTrust

Check the props.conf settings for the sourcetype ingested by the inputs.conf entry.  Chances are the time parsing settings are incorrect.  Verify the TIME_FORMAT and TIME_PREFIX settings in particular.  You may need to add a TZ setting.

---
If this reply helps you, Karma would be appreciated.

tstewart
Explorer
Thank you! Adding the TIME_PREFIX and TIME_FORMAT fixed the issue. I also added the MAX_TIMESTAMP_LOOKAHEAD and TZ as well.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...