So I have a device that will not allow me to adjust the syslog timestamp. As a result, it only sends the message with UTC. As a result, if I want to find the messages that this device has sent, I have to select an absolute time reference and set the search time to the current time in UTC. Once I do this, the messages do return, but if I select last 5 minutes, they do not return. Even if I select “ALL MESSAGES” those messages from the device do not return.
Why does the relative time reference not take into account the messages that were received from this device with the UTC timestamp? Could I have a configuration issue? Is this a bug?
Any help would be appreciated.