Getting Data In

How to fix time for the Index, Source and Timeline graph so they the same?

kwaingrow
Path Finder

Set up: The system clocks for our Searcher and Indexers run GMT, our events are coming from servers posting in PST, EST and GMT.

I have 2 questions/Issues:
1) The index, Source, and timeline display time are all different and out of sync. How can I get them in sync? (see picture: http://www.ugu.com/splunk/time.jpg)

2) One indexer displays the Index time in GMT and all of our other indexers display the index time the same as the event source time. What would make this one indexer different from the rest.

1 Solution

kwaingrow
Path Finder

Resolved: Restart of Splunk Searcher resolved the issue.

View solution in original post

0 Karma

kwaingrow
Path Finder

Resolved: Restart of Splunk Searcher resolved the issue.

0 Karma

kwaingrow
Path Finder

ooops, Sorry. Version 4.2.3-105575

Also #2 has been resolved after a reboot of the server had been preformed.

But #1 display time on the top graph is not the same as the indexed time or the source time. Could this be a bug in the version we are running? http://www.ugu.com/splunk/time.jpg

0 Karma

piebob
Splunk Employee
Splunk Employee

what version of Splunk are you running?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...