<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk Universal Forwarder timezone incorrect after daylight saving time change? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633051#M108390</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254370"&gt;@lesliejones3&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The best place to confirm is via the universal forwarder releases notes (ensure correct major version selected).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.10/Forwarder/Fixedissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.10/Forwarder/Fixedissues&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;A quick look under fixed issues shows v8.2.2 has the fix, so, sadly, you will be affected on your current 8.2.1 version.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_0-1677786666816.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24154i113832C3EBF601E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_0-1677786666816.png" alt="yeahnah_0-1677786666816.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 19:53:40 GMT</pubDate>
    <dc:creator>yeahnah</dc:creator>
    <dc:date>2023-03-02T19:53:40Z</dc:date>
    <item>
      <title>Why is Splunk Universal Forwarder timezone incorrect after daylight saving time change?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550012#M91346</link>
      <description>&lt;P&gt;Using Splunk UF 8.1.1, we've noticed an issue where the Linux x64 forwarder running on RedHat 7.7 did not seem to correctly adjust for daylight saving time; that is, the timestamps after the DST change are 1 hour ahead of where they should be.&lt;/P&gt;
&lt;P&gt;We are not using any special TZ configuration on the UF or indexer and have until now relied on the Splunk UF picking up the underlying OS timezone to enrich events which, as I understand from the props.conf spec, is a supported approach.&lt;/P&gt;
&lt;P&gt;Simply restarting the UF has resolved the issue on multiple servers.&lt;/P&gt;
&lt;P&gt;The same UF version on Windows did not have this issue.&lt;/P&gt;
&lt;P&gt;Is this expected behavior?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 16:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550012#M91346</guid>
      <dc:creator>mattbg</dc:creator>
      <dc:date>2022-04-04T16:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder timezone incorrect after daylight saving time change</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550014#M91347</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is not expected behaviour, how are you sending logs to Indexer? From UF -&amp;gt; Indexer OR UF -&amp;gt; Intermediate UF -&amp;gt; Indexer?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 13:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550014#M91347</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2021-04-30T13:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder timezone incorrect after daylight saving time change</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550027#M91350</link>
      <description>&lt;P&gt;UF -&amp;gt; Indexer&lt;/P&gt;&lt;P&gt;It's a small installation; no clustering (yet); all Splunk Enterprise components are on a single node.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 14:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550027#M91350</guid>
      <dc:creator>mattbg</dc:creator>
      <dc:date>2021-04-30T14:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder timezone incorrect after daylight saving time change</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550028#M91351</link>
      <description>&lt;P&gt;I'll suggest to open support case with splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 14:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/550028#M91351</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2021-04-30T14:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder timezone incorrect after daylight saving time change</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/560486#M92644</link>
      <description>&lt;P&gt;To close this off, I was advised by support that this is a defect fixed in Splunk 8.1.5 (assume this refers to the UF, but didn't enquire as we have plans to upgrade both Enterprise and the UF to 8.2.x)&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 14:46:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/560486#M92644</guid>
      <dc:creator>mattbg</dc:creator>
      <dc:date>2021-07-22T14:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder timezone incorrect after daylight saving time change</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/592115#M103658</link>
      <description>&lt;P&gt;Just experienced this issue on UF 8.1.3 (UF release notes show 8.1.6 has fix) and I'm updating this topic with what we found, in case anyone else comes acrtoss this issue and may find it useful.&lt;BR /&gt;&lt;BR /&gt;DST change occurred&amp;nbsp;(summer time ended, so fallback in our case) on Sunday morning after which we noted this issue.&amp;nbsp; It was only occurring for UF events where the log data did not have timestamped events containing a TZ offset (e.g. +1200).&amp;nbsp; So not all data was affected.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On the Sunday we restarted the UFs/HFs/and even the IDXs to try and resolve the issue, but nothing worked so raised a case with Splunk support.&lt;BR /&gt;&lt;BR /&gt;On Monday, while investigating this issue further, we restarted the UF again and noted that it now fixed the problem and the _time offset was now applied correctly.&lt;BR /&gt;&lt;BR /&gt;So, a UF restarts worked but not until 24 hours after DST change, or maybe until the next day.&amp;nbsp; &amp;nbsp;The UF will still need to be restarted after this time to workaround this bug.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; this issue occurs for both DST change overs periods - fall back (-1h) and spring forward (+1h).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 22:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/592115#M103658</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2022-08-18T22:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder timezone incorrect after daylight saving time change</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/592202#M103667</link>
      <description>&lt;P&gt;We saw this again on some of our Windows UFs that had not yet been upgraded past 8.1.2 (it's the 8.1.5 release notes that show the fix).&lt;/P&gt;&lt;P&gt;However, we did not see the issue on any of our UNIX UFs that are on 8.2.5, which is a good sign given that the large majority of our UFs are UNIX.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 12:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/592202#M103667</guid>
      <dc:creator>mattbg</dc:creator>
      <dc:date>2022-04-04T12:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Universal Forwarder timezone incorrect after daylight saving time change?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633046#M108389</link>
      <description>&lt;P&gt;I have seen some different versions of the UF mentioned.&amp;nbsp; Is there a specific version and later that resolves the DLST issue.&amp;nbsp; We are coming up on March 12, 2023 and DLST will be back.&amp;nbsp; We have a large number of UF's at 8.2.1 and I'm worried we will see this issue pop up.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 18:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633046#M108389</guid>
      <dc:creator>lesliejones3</dc:creator>
      <dc:date>2023-03-02T18:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Universal Forwarder timezone incorrect after daylight saving time change?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633051#M108390</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254370"&gt;@lesliejones3&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The best place to confirm is via the universal forwarder releases notes (ensure correct major version selected).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.10/Forwarder/Fixedissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.10/Forwarder/Fixedissues&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;A quick look under fixed issues shows v8.2.2 has the fix, so, sadly, you will be affected on your current 8.2.1 version.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_0-1677786666816.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24154i113832C3EBF601E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_0-1677786666816.png" alt="yeahnah_0-1677786666816.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 19:53:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633051#M108390</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-03-02T19:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk Universal Forwarder timezone incorrect after daylight saving time change?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633052#M108391</link>
      <description>&lt;P&gt;Thank you for the reply.&amp;nbsp; Now it's time to see how many I can upgrade before the 12th.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 19:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-Universal-Forwarder-timezone-incorrect-after/m-p/633052#M108391</guid>
      <dc:creator>lesliejones3</dc:creator>
      <dc:date>2023-03-02T19:57:36Z</dc:date>
    </item>
  </channel>
</rss>

