Getting Data In

splunk app for palo Alto , Time Zone issue in the logs we received

SunilMaharishi
Path Finder

Hello Team ,

we have strange issue with the logs we receive from palo alto devices , we have app/addon installed and as i see props.conf file has time zone configured as TZ=GMT for these logs and devices who are sending logs are also in GMT only .

Now when i search logs in search head with real time windows it shows correct logs .

But if i select logs for last 4 hours 60 minutes etc . it shows alert where event time is delayed by 8 hours. that is last event it shows is 8 hours earlier.

when i select all time it will show current event from firewall for eg :- if current time is 2PM UTC then event shown is 2PM
and splunk user time it shows is 10 PM PST in the logs listed .

I am not sure what is wrong as sourcetypes are having TZ=GMT configured but still looks like splunk is adding 8 hours in it as my splunk servers are in pst.

Tags (1)
0 Karma
1 Solution

SunilMaharishi
Path Finder

solved the problem

View solution in original post

0 Karma

SunilMaharishi
Path Finder

solved the problem

0 Karma

GW
Engager

There is a very special, and very warm, place for people who DON'T POST THE SOLUTION! !#@$!@#$%@#$%@$#^

ashajambagi
Communicator

What was the solution?

0 Karma

DBattisto
Communicator

How did you solve this issue?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...