Getting Data In

How to fix time for the Index, Source and Timeline graph so they the same?

kwaingrow
Path Finder

Set up: The system clocks for our Searcher and Indexers run GMT, our events are coming from servers posting in PST, EST and GMT.

I have 2 questions/Issues:
1) The index, Source, and timeline display time are all different and out of sync. How can I get them in sync? (see picture: http://www.ugu.com/splunk/time.jpg)

2) One indexer displays the Index time in GMT and all of our other indexers display the index time the same as the event source time. What would make this one indexer different from the rest.

1 Solution

kwaingrow
Path Finder

Resolved: Restart of Splunk Searcher resolved the issue.

View solution in original post

0 Karma

kwaingrow
Path Finder

Resolved: Restart of Splunk Searcher resolved the issue.

0 Karma

kwaingrow
Path Finder

ooops, Sorry. Version 4.2.3-105575

Also #2 has been resolved after a reboot of the server had been preformed.

But #1 display time on the top graph is not the same as the indexed time or the source time. Could this be a bug in the version we are running? http://www.ugu.com/splunk/time.jpg

0 Karma

piebob
Splunk Employee
Splunk Employee

what version of Splunk are you running?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...