Closed danbarr closed 3 years ago
hi @danbarr we have create a ticket to fix this and will update you soon once its been merged. Thanks!
resolved in v1.1.0 of splunk integration... https://github.com/jfrog/log-analytics/blob/master/log-vendors/splunk/fluent.conf.rt#L247
Events from most of the Artifactory and Xray log files were being ingested into Splunk with a timestamp exactly 4 hours in the future (my servers are in UTC-0400 time zone). To fix this, I had to add
use_fluentd_time false
to td-agent.conf. I added this in the final <match jfrog.**> section but I don't know if it would be better to set it on each source.According to the Fluentd docs, I believe this should indeed be set to false, since you're using the timestamp from the original records.