Splunk Search

_time is not picking properly ?

rakesh_498115
Motivator

Hi..

I have configured splunk to pick the _time from the logs . i.e that is BST time in my log . but all of a sudden _time is showing the values in IST time .. couldnt understand wat happend suddenly ??

2013-05-08/L:DATE

this is timestamp that is available in my log . so ideally _time should be 5/8/13:17:22:11.618 but it is showing as 5/8/13:5:22:11.618 . Previously it used to pick the BST time which is available in log.. Pls help .where i can fix this issue ??

Tags (1)
0 Karma

Drainy
Champion

I'm a little confused as IST appears to be 5:30 ahead of BST? but that is a bit more than that.

Anyway, at a first guess have you gone into your user profile and changed your local timezone? Splunk will use this to adjust the timestamp to appear in your local time, so the event may be correct but the displayed time is different.

If the event is now different then your data source has a timestamping issue

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...