You are on page 1of 5

Splunk Enterprise

Troubleshooting
Use Cases

9
Soft Mania

Timestamp Issues
Issue: Event timestamp & _time field
is not matching
Scenario-1: All events are showing
same Timestamp (current timestamp)

2024-03-01 20:12:12
2024-03-01 20:12:12
2024-03-01 20:12:12
2024-03-01 20:12:12
2024-03-01 20:12:12
2024-03-01 20:12:12

@SoftMania #SoftMania
Soft Mania

Timestamp Issues
Root Cause:
Event timestamp is not in the standard format.

Sun_Jan29 122443 EST-05:00 2024 2024-03-01 20:12:12

Sun_Jan29 122445 EST-05:00 2024 2024-03-01 20:12:12


Sun_Jan29 122448 EST-05:00 2024 2024-03-01 20:12:12
Sun_Jan29 122653 EST-05:00 2024 2024-03-01 20:12:12
Sun_Jan29 122958 EST-05:00 2024 2024-03-01 20:12:12
Sun_Jan29 123558 EST-05:00 2024 2024-03-01 20:12:12

@SoftMania #SoftMania
Soft Mania

Data Forwarding Issues


Solution:
Configure your custom timestamp format in
the sourcetype, as shown below in
props.conf file

@SoftMania #SoftMania

You might also like