<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with the Timezone conversion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642443#M109482</link>
    <description>&lt;P&gt;Also please check the below image.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk3.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25256i6321B944C07683B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk3.JPG" alt="Splunk3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2023 20:02:00 GMT</pubDate>
    <dc:creator>varunesh</dc:creator>
    <dc:date>2023-05-05T20:02:00Z</dc:date>
    <item>
      <title>Help with the Timezone conversion?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642431#M109477</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Good Day.&lt;/P&gt;
&lt;P&gt;Need help in Splunk data receiving.&lt;/P&gt;
&lt;P&gt;We have Avamar backup node which is sending the data to splunk is in EST time zone.&lt;/P&gt;
&lt;P&gt;The splunk server is configured with the UTC time zone.&lt;/P&gt;
&lt;P&gt;The data is being received by splunk which shows the correct time but when the index server parsing the data, thinking it was 4 hours old data and ignoring it. So backup failures are not captured and ticket is not generating for backup failures.&lt;/P&gt;
&lt;P&gt;Upon verifiying in splunk side, some of the received data between _time &amp;amp; indextime difference of 4 hours and some of them receving correctly. When the difference time is 4 hours splunk is ignoring the data and not generating ticket for failures.&lt;/P&gt;
&lt;P&gt;Note: The search is running for every 15 minutes if we increase the search duration to see last 4 hours then we will receive lot of duplicates.&lt;/P&gt;
&lt;P&gt;We have contacted Dell support but they are updating me that backup application just send the data with the MIB file as it when receives the data. It would be the splunk to process the data correctly.&lt;/P&gt;
&lt;P&gt;Please help to solve the issue and any recommendation is appreciated.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25252i166AECDBA70792B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk1.PNG" alt="Splunk1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25253i0451794F35FF30CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk2.PNG" alt="Splunk2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 10:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642431#M109477</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-08T10:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642438#M109480</link>
      <description>&lt;P&gt;This often is caused by an incorrect &lt;FONT face="courier new,courier"&gt;TIME_PREFIX&lt;/FONT&gt; setting or an incorrect/missing &lt;FONT face="courier new,courier"&gt;TZ&lt;/FONT&gt; setting in props.conf.&amp;nbsp; Without a specified time zone, Splunk will assume the event occurred in the system time zone, resulting in events being off by hours.&lt;/P&gt;&lt;P&gt;Please share the props.conf settings for the sourcetype.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 19:48:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642438#M109480</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-05T19:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642441#M109481</link>
      <description>&lt;P&gt;Thanks for the reply, can you please let me know how to access the props.conf file? Do I need to capture the configuration file from Avamar or it will be in splunk server? I have access to splunk cloud where we access our jobs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know the procedure to access the file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 19:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642441#M109481</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-05T19:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642443#M109482</link>
      <description>&lt;P&gt;Also please check the below image.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk3.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25256i6321B944C07683B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk3.JPG" alt="Splunk3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 20:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642443#M109482</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-05T20:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642449#M109483</link>
      <description>&lt;P&gt;Since this is Splunk Cloud, you should be able to view the props via the UI (if you have permissions).&amp;nbsp; Go to Settings-&amp;gt;Source types and select the sourcetype used for Avamar data.&amp;nbsp; Click on the Advanced tab to see all of the settings in one place.&lt;/P&gt;&lt;P&gt;These settings should be in an app that is stored somewhere on-prem, ideally in a source code management system.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 21:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642449#M109483</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-05T21:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642661#M109544</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I checked my access and dont have permission to view the prop.conf will reach out to my splunk admins.&lt;/P&gt;&lt;P&gt;I have couple of questions&lt;/P&gt;&lt;P&gt;1. If I change the&amp;nbsp;&lt;FONT face="courier new,courier"&gt;TIME_PREFIX&amp;nbsp;&lt;/FONT&gt;&lt;SPAN&gt;setting&amp;nbsp;i&lt;/SPAN&gt;n the prop.conf, it applies only to our Avamar configuration or it applies to the entire splunk configuration?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; If the setting applies to the entire configuration is there a option to change it only for our Avamar reporting only?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 13:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642661#M109544</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-09T13:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642677#M109547</link>
      <description>&lt;P&gt;It depends on where &lt;FONT face="courier new,courier"&gt;TIME_PREFIX&lt;/FONT&gt; is placed in the props.conf file.&amp;nbsp; If it's in the &lt;FONT face="courier new,courier"&gt;[default]&lt;/FONT&gt; stanza then it will apply to all sourcetypes.&amp;nbsp; This is not recommended.&lt;/P&gt;&lt;P&gt;The settings should be in (and would only apply to) a specific stanza, either for a sourcetype, source, or host.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 14:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642677#M109547</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-09T14:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642707#M109554</link>
      <description>&lt;P class="lia-align-left"&gt;I have received the content of props.conf and I searched for both the keywords&amp;nbsp;&lt;SPAN&gt;TIME_PREFIX &amp;amp;&amp;nbsp;&lt;FONT face="courier new,courier"&gt;TZ&lt;/FONT&gt;&amp;nbsp;but I found some entries for TIME_PREFIX only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Please check the attached images and update back.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Even I searched for Avamar keyword but dont find any entries in the conf file and also for logging using syslog I have attached those contents too from the conf file.&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25297iA1654740ADFF656B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Snap1.JPG" alt="Snap1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap2.JPG" style="width: 583px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25296i90B79593A6462955/image-size/large?v=v2&amp;amp;px=999" role="button" title="Snap2.JPG" alt="Snap2.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snap3.JPG" style="width: 610px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25298i3EF2EA9A531BC5E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Snap3.JPG" alt="Snap3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 17:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642707#M109554</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-09T17:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642723#M109556</link>
      <description>&lt;P&gt;It's difficult to know if a TIME_PREFIX setting is correct without seeing sample data.&amp;nbsp; The props.conf stanzas that do not have a TIME_FORMAT setting probably need one.&lt;/P&gt;&lt;P&gt;If you can't find a stanza for Avamar (did you try btool?) then you probably need one.&amp;nbsp; Every sourcetype should have one.&amp;nbsp; The search results in your OP should say what sourcetype was used with the Avamar events.&amp;nbsp; Make sure there are props.conf settings for that sourcetype.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 19:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642723#M109556</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-09T19:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642874#M109573</link>
      <description>&lt;P&gt;I found the stanza name "avamar " by providing the sourcetype in the table query. I verified the prop.conf but couldn't find any stanza named avamar.&lt;/P&gt;&lt;P&gt;In the other defined sanza in prop.conf they have used the below for the TIME_PREFIX setting&lt;/P&gt;&lt;P&gt;TIME_PREFIX = \[&lt;/P&gt;&lt;P&gt;As we need to update the&amp;nbsp;TIME_PREFIX setting specific only to our Avamar host, can you please let me know the syntax for the TIME_PREFIX setting to set specific host or IP to the UTC time zone?&lt;/P&gt;&lt;P&gt;Also please share any technote to understand the syntax and other options in&amp;nbsp;TIME_PREFIX setting.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 15:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642874#M109573</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-10T15:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642896#M109575</link>
      <description>&lt;P&gt;The Avamar props may not be in a stanza called "avamar".&amp;nbsp; It could be in a source-specific or host-specific stanza.&lt;/P&gt;&lt;P&gt;I think it may be a good idea to specify &lt;FONT face="courier new,courier"&gt;TIME_PREFIX&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;TZ&lt;/FONT&gt; separately, since &lt;FONT face="courier new,courier"&gt;TZ&lt;/FONT&gt; is specific to the machine and &lt;FONT face="courier new,courier"&gt;TIME_PREFIX&lt;/FONT&gt; is specific to the data.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[host::&amp;lt;&amp;lt;host name&amp;gt;&amp;gt;]
TZ = EST

[source::&amp;lt;&amp;lt;Avamar file path&amp;gt;&amp;gt;]
# This setting is an assumption.  Examine sample data to verify it is correct
TIME_PREFIX = \[&lt;/LI-CODE&gt;&lt;P&gt;Replace words in &lt;FONT face="courier new,courier"&gt;&amp;lt;&amp;lt;&amp;gt;&amp;gt;&lt;/FONT&gt; with actual values (omitting the brackets).&lt;/P&gt;&lt;P&gt;The tech notes for all config files are in $SPLUNK_HOME/etc/system/README/*.spec&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 17:49:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642896#M109575</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-10T17:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642901#M109576</link>
      <description>&lt;P&gt;I have prepared based on your input please confirm.&lt;/P&gt;&lt;P&gt;[avamar]&lt;BR /&gt;[host::usxxxx*]&lt;BR /&gt;TZ = US/Eastern&lt;BR /&gt;TIME_PREFIX = \[&lt;/P&gt;&lt;P&gt;I dont understand the below line&lt;BR /&gt;[source::&amp;lt;&amp;lt;Avamar file path&amp;gt;&amp;gt;]&lt;/P&gt;&lt;P&gt;Avamar bkp failure data is being sent from Avamar server to syslog server as when the failures occur , which means in Avamar we configured to send the data to syslog server and splunk avamar data is being indexed from the syslog server, so what is the source I need to mention here?&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 18:19:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642901#M109576</guid>
      <dc:creator>varunesh</dc:creator>
      <dc:date>2023-05-10T18:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with the Timezone conversion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642909#M109577</link>
      <description>&lt;P&gt;I forgot you're using syslog.&amp;nbsp; Sorry about that.&amp;nbsp; In that case, have the syslog server write Avamar data to a different location (how to do this depends on your syslog server).&amp;nbsp; When Splunk reads from that location, it can associate the appropriate props settings.&lt;/P&gt;&lt;P&gt;Do NOT do this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[host::usxxxx*]
TZ = US/Eastern
TIME_PREFIX = \[&lt;/LI-CODE&gt;&lt;P&gt;This will tell Splunk to look for a timestamp after a left bracket in ALL data that comes from the usxxxx host.&amp;nbsp; Unless that host provides a single type of data, that likely to be an incorrect setting.&amp;nbsp; The TIME_PREFIX setting needs to be associated with a specific source or sourcetype rather than a specific host.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 19:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-the-Timezone-conversion/m-p/642909#M109577</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-10T19:30:36Z</dc:date>
    </item>
  </channel>
</rss>

