What would cause times to be off on received logs? I installed the UF on a server yesterday that had the correct time. If I search for "All Time" for that host, I receive log entries for 8/1/2018, but if I specify ANY time range - last 7 days, last 24 hours, etc., it shows the correct time. Is this a bug in Splunk?
The date is exactly what appears to be in the event data 08/01/2018 10:45:51 PM
. so it is just using the date in the event for the timestamp. This is perfectly logical and valid for Splunk to do. You certainly can have future dates in your data, if that is the date that is considered valid in the event (or not, if it is just using the wrong date from the event data).