All Apps and Add-ons

REST API Modular Input: Why is the timestamp on all my events 1 hour off and how do I fix this?

CSummersDOT
Explorer

Just installed the REST API Modular Input and love it so far, but I'm having 1 major issue. The timestamp on all of my events from this module are 1 hour ahead of my current time. Anything I can do to fix this? It's breaking the relative search in my dashboard.

0 Karma
1 Solution

CSummersDOT
Explorer

Found it. Pretty stupid of me, I didn't realize the json from the web api ad a datetime in it and it's 1 hour off.

View solution in original post

0 Karma

CSummersDOT
Explorer

Found it. Pretty stupid of me, I didn't realize the json from the web api ad a datetime in it and it's 1 hour off.

0 Karma

knutsod
Path Finder

You can tell splunk to use its own time for _time and not try and look it up in the event, but I would recommend just fixing the source if you can for accuracy.

knutsod
Path Finder

Are you referring to the _time field?

0 Karma

CSummersDOT
Explorer

Yes, _time. My other inputs are showing correct time but the REST and Command apps aren't. Couldn't find any reference to a TZ change in any prop.confs. No idea where to look now. Even read through the python script and all it does is return the json strong.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...