I'm trying to figure out which search will most accurately tell me when events with future timestamps are being detected.
Somebody on the team built this search:
| tstats min(_time) as earliest_time, max(_time) as latest_time by index
| eval daysOfLogs=round((latest_time - earliest_time)/60/60/24, 2)
| eval eventsInFuture=if(latest_time > now(), "yes", "no")
| eval tnow = now()
| convert ctime(*time)
| lookup index_to_env index
| convert ctime(tnow)
That search doesn't show any sourcetypes with future data.
This search, on the other hand, shows that multiple sourcetypes are showing future timestamps:
| metadata type=sourcetypes index=* index!=_* | eval now=now() | eval futuretime=lastTime-now | where futuretime>0
Based on what I've seen searching on the raw events with a "latest=+20d@d", the tstats command is the one that isn't seeing the future events...
Any idea what is causing this behavior?
... View more