This comes from a Infoblox appliance using a built in UF. I am catching this on a HF which acts almost as an intermediate forwarder, this is used because we don't want to have other products send directly to our indexers.
This is the inputs.conf file on the HF: (Again, it appears that even if I change the index or sourcetype parameters, nothing changes data wise)
index = dns
sourcetype = infoblox
props.conf on HF and IN (tried in both with same config): This is my current config.
TZ = UTC
I also tried your settings above and these were my inputs, again, no settings I adjust are effecting the data:
TIME_PREFIX = ^
TIME_FORMAT = %s
MAX_TIMESTAMP_LOOKAHEAD = 11
Correct me if I'm wrong, but if the events were pulling the timezone from the "machine instance" the date_zone would show as "local", this is what is stated in the docs. My events are showing a date_zone of "0".
Current user timezone preferences are Eastern (GMT-5:00). This value doesn't matter though, for example if I set this to a UTC/GMT equivalent of the correct timezone of the timestamps, I still need to search back almost 4-5 hours to get real time events. This would indicate that the timestamps are being interpreted incorrectly at index time I would presume.
The search result is as follows:
_time is showing the timestamp in EST time and I have to search back almost 4-5 hours to get recent results so this is not a search time problem.
... View more