When searching through certain sour ectypes and indexes, seeing a discrepancy between time and date for event time. Suggestions welcomed on diagnosing this issue.
Thanks in advance.
I would start by looking at timestamp parsing configuration for those sourcetypes.
Reference: https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Configuretimestamprecognition