Getting Data In

Why is the event timestamp and the timestamp within my results different depending on the search?

karthi2809
Builder

My event timestamp and timestamp within my results are not same while i am searching in Splunk Web but some scenarios it's working fine. i attached the screen shots below.

Correct:
alt text

Wrong
alt text

Tags (1)
0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@karthi2809 - Did the answer provided by lguinn help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

lguinn2
Legend

The most likely answer is this: the log file is probably recording the data in the local time zone of the host. That is the time that you see in the body of the Event.
When the data is indexed into Splunk, the timestamp (the Time column in the screen shot) is converted to UTC and then stored with the original event data.
When you search, the timestamp is displayed, the Time column is displayed in the timezone that you have chosen as a user.

For some data, it is likely that your user timezone is the same as the original data, so it matches. For other data (hopefully collected from a server in a different timezone), it won't match. If this seems wrong to you, then you should confer with your Splunk Administrator to ensure that the timestamps/timezones are being extracted properly when the data is ingested into Splunk.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...