Hi,
Hi,
Yes I see that logs are indexing, but If I want to search for current log then I have to search for last 4 hours. I mean indexing time stamp is 4 hour behind.
If I search for last 4 hours in the search, I can see the latest logs there.
We have the same forwarder on linux machines and that is giving proper time stamps. This is happening on windows server's universal forwarder. All our universal forwarder machines are in same time zone but not indexer.
Thanks ,
Abilan
... View more