# Log entries not in correct order because of identical timestamp

**URL:** <https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718>\
**Category:** Graylog Central (peer support)\
**Created:** [June 13, 2024, 2:33pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718 "2024-06-13T14:33:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Smarties](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Smarties](https://community.graylog.org/u/Smarties)\
**Post date:** [June 13, 2024, 2:33pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718/1 "2024-06-13T14:33:17Z")

</div>

Hello,  
at the moment i am trying to migrate to graylog from very basic textfiles where i am currently logging my agents.  
The problem is that i am used to having all my log entries in order and since my agents are quite fast at logging there are multiple log entries for the same timestamp.  
Since graylog uses the timestamp to order my messages, the messages that have the same timestamp will now be shown in random order which is confusing.

Here are the log messages in graylog search:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/9/4/9488df964be2796a49f2a95cd0d1a1ef5e74c093.png)

I am currently on Graylog version: 5.0.2

I have tried to come up with a solution to this problem but since i am new to graylog i could not think of a valid solution that would help me

I would like to know how other people deal with this problem or if it just is not a problem to them and they dont care

---

<div class="post-metadata">

**Author:** ![Smarties](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Smarties](https://community.graylog.org/u/Smarties)\
**Post date:** [June 13, 2024, 2:34pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718/2 "2024-06-13T14:34:26Z")

</div>

Here are the messages in my textfile:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/5/d/5df13593878da26f1d3ab5ca264f6b5f41e519fa.png)

(Could not have two images in my post since i am new)

---

<div class="post-metadata">

**Author:** ![joe.gross](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/joe.gross/32/13372_2.png) [@joe.gross](https://community.graylog.org/u/joe.gross)\
**Post date:** [June 13, 2024, 9:57pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718/3 "2024-06-13T21:57:09Z")

</div>

Well, your logs all list the same timestamp. That’s what Graylog gets.

I will look into it and report back.

---

<div class="post-metadata">

**Author:** ![joe.gross](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/joe.gross/32/13372_2.png) [@joe.gross](https://community.graylog.org/u/joe.gross)\
**Post date:** [June 13, 2024, 11:40pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718/4 "2024-06-13T23:40:03Z")

</div>

OK. I’ve got some good news.

There are two possible problems here. First, the agent you are using may be collecting these messages then delivering them in a different order than that in the original file. If that’s the case, there’s not much Graylog can do for you, because that’s the order in which they are arriving.

However, if the agent is delivering them in the same order they are read, the trouble may lie in Graylog itself. At least your version of Graylog.

In version 5.1, we fixed the exact issue you are experiencing by adding a ULID for each message received. This allows for sorting by ULID, even when the timestamps are identical.

You need only to upgrade and it will be resolved. That is, provided your agent is delivering them as read.

> <https://github.com/Graylog2/graylog2-server/pull/6711>
>
> The ULID format in the \`gl2\_message\_id\` field is composed of a 48 bit timestamp …followed by 80 bits
> of randomness.
> Use the first 16 bits of the random field to embed a sequence number
> for each message.
> If a batch of messages was received with identical timestamps
> (the same millisecond), the original receive order is kept by the
> encoded sequence number which directly follows the timestamp.
> 
> This allows us to sort messages by \`gl2\_message\_id\` which should have the correct original
> order in most cases.
> 
> \## CAVEATS
> This is a best effort approach to a complicated problem. It's not a silver bullet.
> Here are reasons why the \`gl2\_message\_id\` sort order might not always be correct:
> 
> \- The sequence number is generated per node and input. 
> This means that sorting will not work if an input is load balanced over multiple nodes.
> 
> - There is only space for \`60535\` messages with the same timestamp and input.
> 
> \- Also, there is a small chance that, if too many batches of messages with the same timestamp and input get processed
> in parallel, the sort order might be wrong. 
> 
> \## Performance Impact
> 
> Running a benchmark, which ingests 8 million messages.
> Four parallel curl loops send batches of \`5000\` messages with identical timestamps.
> 
> Without this change, this takes \`3m 19s\`
> With this change: \`3m 25s\` 
> 
> Which means approx 40k msg/sec and no measurable performance impact.
> 
> 
> Fixes #2741

---

<div class="post-metadata">

**Author:** ![Smarties](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Smarties](https://community.graylog.org/u/Smarties)\
**Post date:** [June 14, 2024, 2:30pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718/5 "2024-06-14T14:30:50Z")

</div>

Thank you for the quick reply

I will try and update Graylog in the next few days to check the solution but this should fix my problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 28, 2024, 2:31pm UTC](https://community.graylog.org/t/log-entries-not-in-correct-order-because-of-identical-timestamp/32718/6 "2024-06-28T14:31:38Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
