All Apps and Add-ons

Solarwinds Alerts Timestamp issue

brandonf
Path Finder

Howdy

We have installed and configured the add-on and data is being retrieved. However we notice that the timestamp on the alert events is wrong - it seems to be exactly 2 hours behind. We check the SQL eventtime and it is correct there but the script seems to to be incorrectly interpreting the timestamp?

The format in the database is YYYY-mm-dd HH:MM:SS.3N but Splunk shows YYYY-mm-ddTHH:MM:SS.XXXXXX

Thanks
B

0 Karma

ankurpwc
Engager

HI brandonf,

Have you found solution for this ? we too are facing exactly same issue.

0 Karma

neltavares
New Member

We are noticing the exact same behavior as described above, but in our case we are exactly 5 hours behind, which coincides with the difference between our time zone (Eastern Standard) and UTC time.

Solarwinds is forwarding events to splunk correctly, but the events are from exactly 5 hours ago.
So an alert sent from solarwinds to splunk with the following eventTime: EventTime: 2018-12-18T15:39:16.2600000 actually appeared in solarwinds at 10:39 (and not 15:39).

Has anyone found a way to correct this?

Thanks!

0 Karma

macadminrohit
Contributor

We had similar problem but not in solarwinds app. for this sourcetype you can specifically define TIME_PREFIX and TIME_FORMAT in props.conf since you dont have TZ in the event itself . You can set TZ in props.conf and explicitly let Splunk know which TZ event is in .

See the below link, this should help you.

https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Applytimezoneoffsetstotimestamps

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...