Getting Data In

Time Stamp i(All time vs 15 min)

tmarlette
Motivator

When I do a search on my search head for all time, I see correct time stamps in standard EST. When I do a 15 minute search, I see time stamps from 5 hours ago.

My search head and indexer are both set to CST on the OS, and the logs are coming in in EST which has been defined in props.conf.

Does anyone know why this could be happening?

This is an image of my sourcetype time stamps, vs my system clock (CST).

alt text

Tags (1)
0 Karma
1 Solution

tmarlette
Motivator

In lukejadamec's comments, he mentioned that splunk thought my system time was off. I set the time zone and time settings manually during OS installation, but never checked them after that. When i did, they reflected GMT time.

I adjusted these settings to EST, and all timestamps are current now, and the issue has been resolved.

View solution in original post

tmarlette
Motivator

In lukejadamec's comments, he mentioned that splunk thought my system time was off. I set the time zone and time settings manually during OS installation, but never checked them after that. When i did, they reflected GMT time.

I adjusted these settings to EST, and all timestamps are current now, and the issue has been resolved.

lukejadamec
Super Champion

Yea. This was starting to give me heartburn 🙂

0 Karma

tmarlette
Motivator

negative... but when I looked at my OS on both the indexer and the SH it was in GMT. I set it to CST during install, and didnt' check it after that. I am reconfiguring it now to be in EST and we will see what happens.

0 Karma

lukejadamec
Super Champion

If this is a recent event, then the timestamp is GMT.
Are you configuring the TZ in props.conf on the indexer by host?

0 Karma

tmarlette
Motivator

Raw print of an event for 15 minute search of a sourcetype:

Query:
sourcetype= | table _raw

INFO

0 Karma

lukejadamec
Super Champion

Splunk thinks your system time is GMT, so since your user timezone is set to EST it is adjusting the displayed time. You can check this by setting your user timezone to GMT.
I'm also curious about the timestamps in the _raw output

0 Karma

tmarlette
Motivator

That includes windows Perfmon

0 Karma

tmarlette
Motivator

This is happening on all sourcetypes. I'm sure there is a global setting somewhere that I am missing, but I couldn't tell you what it is to save my life.

0 Karma

lukejadamec
Super Champion

Is this for all data, or just certain sources?

0 Karma

tmarlette
Motivator

This is also happening on any user that logs into my search head.

0 Karma

tmarlette
Motivator

It is set to EST

0 Karma

lukejadamec
Super Champion

What is your splunk user timezone property set to?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...