Getting Data In

splunk app for palo Alto , Time Zone issue in the logs we received

SunilMaharishi
Path Finder

Hello Team ,

we have strange issue with the logs we receive from palo alto devices , we have app/addon installed and as i see props.conf file has time zone configured as TZ=GMT for these logs and devices who are sending logs are also in GMT only .

Now when i search logs in search head with real time windows it shows correct logs .

But if i select logs for last 4 hours 60 minutes etc . it shows alert where event time is delayed by 8 hours. that is last event it shows is 8 hours earlier.

when i select all time it will show current event from firewall for eg :- if current time is 2PM UTC then event shown is 2PM
and splunk user time it shows is 10 PM PST in the logs listed .

I am not sure what is wrong as sourcetypes are having TZ=GMT configured but still looks like splunk is adding 8 hours in it as my splunk servers are in pst.

Tags (1)
0 Karma
1 Solution

SunilMaharishi
Path Finder

solved the problem

View solution in original post

0 Karma

SunilMaharishi
Path Finder

solved the problem

0 Karma

GW
Engager

There is a very special, and very warm, place for people who DON'T POST THE SOLUTION! !#@$!@#$%@#$%@$#^

ashajambagi
Communicator

What was the solution?

0 Karma

DBattisto
Communicator

How did you solve this issue?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...