Splunk Enterprise

Disface on "_time" variable on SPLUNKFORDWARD

gbriones
Engager

Hi,

I have a problem and I can review event exists a disface between variable time extract and "_time" on SPL

file:

T_LOGFILE_VORDEL_ANSWER_SLA10_1;0;08/25/2021 09:03:08

on SPLUNK

gbriones_0-1629906622529.png

 

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the time zone is set correctly in your Splunk preferences.

Verify the data is onboarded correctly.  Check props.conf for the correct TIME_FORMAT setting.  Add a TZ setting so Splunk knows the time zone in which the event was generated.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

gbriones
Engager

add on props.conf and still the problem:

 

...
disabled=false
pulldown_type=true
TZ=America/Santiago
TIME_FORMAT = %m/%d/%Y %H:%M:%S

Tags (1)
0 Karma