Timestamp Issues - Splunk Troubleshooting Use Case - 9

13.06.24 10:46 PM - By Murugan

Timestamp Issues

Issue: 
Event timestamp & _time field do not match
Scenario-1:
All events are showing the same Timestamp (current timestamp)
Root Cause:
Event timestamp is not in the standard format.
Solution: 
Configure your custom timestamp format in the sourcetype, as shown below in props.conf file

Murugan