Dashboards & Visualizations

Question about accuracy of results when specifying the time range

johnblakley
Explorer

What would cause times to be off on received logs? I installed the UF on a server yesterday that had the correct time. If I search for "All Time" for that host, I receive log entries for 8/1/2018, but if I specify ANY time range - last 7 days, last 24 hours, etc., it shows the correct time. Is this a bug in Splunk?

alt text

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

The date is exactly what appears to be in the event data 08/01/2018 10:45:51 PM. so it is just using the date in the event for the timestamp. This is perfectly logical and valid for Splunk to do. You certainly can have future dates in your data, if that is the date that is considered valid in the event (or not, if it is just using the wrong date from the event data).

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...