Splunk Search

_time is not picking properly ?

rakesh_498115
Motivator

Hi..

I have configured splunk to pick the _time from the logs . i.e that is BST time in my log . but all of a sudden _time is showing the values in IST time .. couldnt understand wat happend suddenly ??

2013-05-08/L:DATE

this is timestamp that is available in my log . so ideally _time should be 5/8/13:17:22:11.618 but it is showing as 5/8/13:5:22:11.618 . Previously it used to pick the BST time which is available in log.. Pls help .where i can fix this issue ??

Tags (1)
0 Karma

Drainy
Champion

I'm a little confused as IST appears to be 5:30 ahead of BST? but that is a bit more than that.

Anyway, at a first guess have you gone into your user profile and changed your local timezone? Splunk will use this to adjust the timestamp to appear in your local time, so the event may be correct but the displayed time is different.

If the event is now different then your data source has a timestamping issue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...