Splunk Search

search time an hour plus

adcom26
Explorer

Hello 

when i make a search i got an hour plus 


xxx.jpg

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @adcom26,

you haven't to check the Splunk server time that's correct, but the server that's sending logs, probably it has a different time.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @adcom26,

did you checked the timezone of the data source or the solar time, probably it's different than the one of your Splunk server.

Ciao.

Giuseppe

0 Karma

adcom26
Explorer

I checked it. But is the same

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @adcom26,

the one hour delay is continue or not? in other words: have you alwaus one hur delay or in some moments there's a delay of less than one hour?

if it isn't continue, see how the data are generated: if there's a script or how are generated the written files, because maybe there a delay in generation or copy.

If instead you have a continue delay of exactly one hour this is usually a timezone problem, see in the raw events if the timestamp of the event is the same of the time in the events, if it's the same check what's the real timezone of the data, if it's different, check the props.conf of your sourcetype.

Ciao.

Giuseppe

0 Karma

adcom26
Explorer

HI @gcusello  

 

 

the one hour delay is continue

yyy.jpg

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @adcom26,

as I said, check if the server has the correct time, maybe it hasn't the solar time.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...