<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder Local Clock in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481001#M9412</link>
    <description>&lt;P&gt;I have more than 100 UF deployed and wan to know the date and time of each of the forwarders to be shown in real time basis on a dashboards. How I can read the clock data of a UF on a real time basis?&lt;/P&gt;</description>
    <pubDate>Mon, 02 Mar 2020 08:29:01 GMT</pubDate>
    <dc:creator>santosh_sshanbh</dc:creator>
    <dc:date>2020-03-02T08:29:01Z</dc:date>
    <item>
      <title>Universal Forwarder Local Clock</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481001#M9412</link>
      <description>&lt;P&gt;I have more than 100 UF deployed and wan to know the date and time of each of the forwarders to be shown in real time basis on a dashboards. How I can read the clock data of a UF on a real time basis?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 08:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481001#M9412</guid>
      <dc:creator>santosh_sshanbh</dc:creator>
      <dc:date>2020-03-02T08:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Local Clock</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481002#M9413</link>
      <description>&lt;P&gt;Best practice is that all of your forwarders uses a synchronised time source, in many cases thats likely NTP or the Windows Time Service.&lt;/P&gt;

&lt;P&gt;The problem with your question, is how would you trust what a UF &lt;EM&gt;thinks&lt;/EM&gt; its time is vs what it &lt;EM&gt;really&lt;/EM&gt; is.&lt;/P&gt;

&lt;P&gt;You would be relying on the UF knowing two times - the &lt;EM&gt;real&lt;/EM&gt; time, and its &lt;EM&gt;local&lt;/EM&gt; time.&lt;BR /&gt;
You could write a simple scripted input to query a known good time source like an ntp server, and write its result alongside your UF's local time into a logfile and configure your inputs.conf to collect both times so you could compare any drift (but you can expect a few ms difference between the two even on a perfectly synced system)&lt;/P&gt;

&lt;P&gt;Then, there is your use of the dreaded phrase "real time". At the risk of running away on a tangent, take a look at this post for reasons why "real-time" in your use case is probably a bad idea.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/734767/why-are-realtime-searches-disliked-in-the-splunk-w.html"&gt;https://answers.splunk.com/answers/734767/why-are-realtime-searches-disliked-in-the-splunk-w.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 14:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481002#M9413</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-03-02T14:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Local Clock</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481003#M9414</link>
      <description>&lt;P&gt;Thanks for the inputs. QQ, can you share some thoughts on how to get the time of NTP server? &lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 05:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-Forwarder-Local-Clock/m-p/481003#M9414</guid>
      <dc:creator>santosh_sshanbh</dc:creator>
      <dc:date>2020-03-03T05:53:24Z</dc:date>
    </item>
  </channel>
</rss>

