Splunk Search

_time is not picking properly ?

rakesh_498115
Motivator

Hi..

I have configured splunk to pick the _time from the logs . i.e that is BST time in my log . but all of a sudden _time is showing the values in IST time .. couldnt understand wat happend suddenly ??

2013-05-08/L:DATE

this is timestamp that is available in my log . so ideally _time should be 5/8/13:17:22:11.618 but it is showing as 5/8/13:5:22:11.618 . Previously it used to pick the BST time which is available in log.. Pls help .where i can fix this issue ??

Tags (1)
0 Karma

Drainy
Champion

I'm a little confused as IST appears to be 5:30 ahead of BST? but that is a bit more than that.

Anyway, at a first guess have you gone into your user profile and changed your local timezone? Splunk will use this to adjust the timestamp to appear in your local time, so the event may be correct but the displayed time is different.

If the event is now different then your data source has a timestamping issue

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...