<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is the same timestamp getting indexed differently in two different Splunk servers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146365#M29804</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am using DBConnect to fetch two timestamps from an Oracle database table, let's call them TS1 and TS2, having the following values (&lt;STRONG&gt;TS1 is the time used for indexing the data, whereas TS2 is the Rising Column&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;**TS1                                                     TS2&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;02-JUN-2015 06:05:16                     02-JUN-2015 10:21:14**&lt;/P&gt;

&lt;P&gt;On my local Development system (a &lt;STRONG&gt;Windows&lt;/STRONG&gt; system with Splunk version &lt;STRONG&gt;6.2&lt;/STRONG&gt;), the above data is indexed as it is, i.e. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;TS1  = 02-JUN-2015 06:05:16, TS2 = 02-JUN-2015 10:21:14&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;However, on an Integration Testing Server (a &lt;STRONG&gt;Linux&lt;/STRONG&gt; server with Splunk version &lt;STRONG&gt;6.1.5&lt;/STRONG&gt;), the same data is indexed as:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;TS1 = 02-JUN-2015 06:05:16, TS2 = 02-JUN-2015 **11:21:14&lt;/STRONG&gt;**&lt;/P&gt;

&lt;P&gt;As we can see, only TS2 is off by 1 hour on the Linux server.&lt;/P&gt;

&lt;P&gt;I am not sure why there is this difference between the way Splunk is indexing the Data. I have not made any props.conf changes to any of these two servers related to Time Zone configurations. &lt;/P&gt;

&lt;P&gt;The Windows server is running on UTC with Daylight Saving Time enabled, and the Linux server is in BST.&lt;/P&gt;

&lt;P&gt;Could someone please let me know what could be the reason behind this behaviour of the Linux server (Splunk version 6.1.5).&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jun 2015 16:22:41 GMT</pubDate>
    <dc:creator>SwatiApte</dc:creator>
    <dc:date>2015-06-09T16:22:41Z</dc:date>
    <item>
      <title>Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146365#M29804</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am using DBConnect to fetch two timestamps from an Oracle database table, let's call them TS1 and TS2, having the following values (&lt;STRONG&gt;TS1 is the time used for indexing the data, whereas TS2 is the Rising Column&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;**TS1                                                     TS2&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;02-JUN-2015 06:05:16                     02-JUN-2015 10:21:14**&lt;/P&gt;

&lt;P&gt;On my local Development system (a &lt;STRONG&gt;Windows&lt;/STRONG&gt; system with Splunk version &lt;STRONG&gt;6.2&lt;/STRONG&gt;), the above data is indexed as it is, i.e. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;TS1  = 02-JUN-2015 06:05:16, TS2 = 02-JUN-2015 10:21:14&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;However, on an Integration Testing Server (a &lt;STRONG&gt;Linux&lt;/STRONG&gt; server with Splunk version &lt;STRONG&gt;6.1.5&lt;/STRONG&gt;), the same data is indexed as:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;TS1 = 02-JUN-2015 06:05:16, TS2 = 02-JUN-2015 **11:21:14&lt;/STRONG&gt;**&lt;/P&gt;

&lt;P&gt;As we can see, only TS2 is off by 1 hour on the Linux server.&lt;/P&gt;

&lt;P&gt;I am not sure why there is this difference between the way Splunk is indexing the Data. I have not made any props.conf changes to any of these two servers related to Time Zone configurations. &lt;/P&gt;

&lt;P&gt;The Windows server is running on UTC with Daylight Saving Time enabled, and the Linux server is in BST.&lt;/P&gt;

&lt;P&gt;Could someone please let me know what could be the reason behind this behaviour of the Linux server (Splunk version 6.1.5).&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 16:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146365#M29804</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2015-06-09T16:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146366#M29805</link>
      <description>&lt;P&gt;Hi @SwatiApte&lt;/P&gt;

&lt;P&gt;Would you be able to add what version of DB Connect you're using? DB Connect 1 or DB Connect 2?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 16:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146366#M29805</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-06-09T16:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146367#M29806</link>
      <description>&lt;P&gt;Splunk did a somewhat nasty thing in Splunk v6(dot????  I don't know which version for sure): They changed the precedence rules for &lt;CODE&gt;TZ&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt; and this may be the problem.  In v5 and earlier (and maybe some versions of v6), The only way to set &lt;CODE&gt;TZ&lt;/CODE&gt; was to have a configuration on the indexer (or, if a Heavy Forwarder, on the forwarder).  In v6(?) this was changed and Splunk will honor any &lt;CODE&gt;TZ&lt;/CODE&gt; setting from any forwarder (Universal, Light, Heavy) and this will be propagated internally to the indexers and this will OVERRIDE any setting that was deployed to the Indexers.  This is a &lt;EM&gt;HUGE&lt;/EM&gt; change and could cause a TOTALLY different &lt;CODE&gt;TZ&lt;/CODE&gt; behavior just by upgrading the version of Splunk you are running and changing NOTHING else.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 17:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146367#M29806</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-09T17:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146368#M29807</link>
      <description>&lt;P&gt;Have you checked your time zone preferences for your user.  It defaults to the TZ of the local system. Edit your account  and set Time Zone.   Splunk handles offsets for users.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 21:24:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146368#M29807</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-06-09T21:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146369#M29808</link>
      <description>&lt;P&gt;The DBConnect version is 1.1.6 on both the servers.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 07:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146369#M29808</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2015-06-10T07:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146370#M29809</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;The timezone preference is set to Default in both the servers.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 07:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146370#M29809</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2015-06-10T07:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146371#M29810</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;On both of these servers, we have a single instance of Splunk that does the data capturing, indexing and searching. We do not have separate instances for Forwarders, the TZ configuration would not have been overridden is what I feel.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 07:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146371#M29810</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2015-06-10T07:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146372#M29811</link>
      <description>&lt;P&gt;Unless your Forwarder &lt;EM&gt;is&lt;/EM&gt; your Indexer, then the situation that I described is entirely possible. &lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 12:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146372#M29811</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-10T12:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146373#M29812</link>
      <description>&lt;P&gt;In certain situations (if you do not tell Splunk what the &lt;CODE&gt;TZ&lt;/CODE&gt; value should be), it may use the &lt;CODE&gt;TZ&lt;/CODE&gt; value of the Indexer's host OS; is one Indexer is in a different TZ than the other?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 12:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146373#M29812</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-10T12:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146374#M29813</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Our Forwarder and Indexer is the same Splunk instance.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 12:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146374#M29813</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2015-06-10T12:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146375#M29814</link>
      <description>&lt;P&gt;Thats my point.  When default is set Splunk will use the system Time/ Timezone.  BST is one hour ahead of UTC so thats why your data shows up as off.  In your profile set the TZ to GMT or what ever timezone you want.  Splunk will automatically apply search offsets.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 16:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146375#M29814</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-06-10T16:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146376#M29815</link>
      <description>&lt;P&gt;If your &lt;CODE&gt;TZ&lt;/CODE&gt; value is &lt;CODE&gt;default&lt;/CODE&gt; then you will see this problem; set it to an explicit value; if it is UTC then use:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TZ = UTC
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 10 Jun 2015 16:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146376#M29815</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-10T16:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146377#M29816</link>
      <description>&lt;P&gt;But both the servers are on BST, and both are set to Default Time Zones, then why the difference in results?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 11:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146377#M29816</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2015-06-11T11:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146378#M29817</link>
      <description>&lt;P&gt;It is an interesting question and I would like to know the answer if you ever find it but the solution is to use &lt;CODE&gt;TZ=BST&lt;/CODE&gt;, in any case.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 14:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146378#M29817</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-11T14:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146379#M29818</link>
      <description>&lt;P&gt;Forgive me for not noticing this earlier (you said it clearly enough) but your problem is not with &lt;CODE&gt;TS1&lt;/CODE&gt; (which Splunk is using for &lt;CODE&gt;timestamping&lt;/CODE&gt; and setting the &lt;CODE&gt;_time&lt;/CODE&gt; value for each event) but with &lt;CODE&gt;TS2&lt;/CODE&gt; which is a &lt;CODE&gt;non-timestamp&lt;/CODE&gt; time that is &lt;EM&gt;inside&lt;/EM&gt; the data.  If that is really the case then what you are saying makes absolutely no sense at all.&lt;/P&gt;

&lt;P&gt;First of all, Splunk will never (without some serious configuration work on your part) re-write data inside an event; it is always preserved, indexed, and passed back to searches as it was when it was received/forwarded.&lt;BR /&gt;
Secondly, all of Splunk's &lt;CODE&gt;time&lt;/CODE&gt; and &lt;CODE&gt;TZ&lt;/CODE&gt; settings apply ONLY to the &lt;CODE&gt;timesteamp&lt;/CODE&gt; (i.e. to &lt;CODE&gt;_time&lt;/CODE&gt;). &lt;/P&gt;

&lt;P&gt;The only way that what you are saying makes sense is if the &lt;EM&gt;generator&lt;/EM&gt; of the data (a combination of &lt;CODE&gt;DB Connect&lt;/CODE&gt; and your DB) is behaving differently when you connect from Dev vs. when you connect from Integration.  I will admit that I am light on my &lt;CODE&gt;DB Connect&lt;/CODE&gt; experience but I do know that &lt;CODE&gt;v2&lt;/CODE&gt; is very different from previous versions so have you upgraded to &lt;CODE&gt;v2&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;Another thing to check is to ensure that  your &lt;CODE&gt;SQL user&lt;/CODE&gt;, your &lt;CODE&gt;SQL string&lt;/CODE&gt;, and your &lt;CODE&gt;DB Connection&lt;/CODE&gt; is identical between the 2 servers.  I have a strong suspicion that this is not the case and that whatever difference you find will be the root cause of the discrepancy.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2015 19:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146379#M29818</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-14T19:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the same timestamp getting indexed differently in two different Splunk servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146380#M29819</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Further to this, we created a simple java program that connects to the database and prints a single record. We executed this program from both our local Development system and on the Integration Testing server. We used a simple &lt;STRONG&gt;resultSet.getTimeStamp&lt;/STRONG&gt; function on the result. We noticed that both the systems are returning the same value for each of the datetime attributes. Ex: "2015-06-18 09:48:35.0"&lt;/P&gt;

&lt;P&gt;The issue is &lt;STRONG&gt;only&lt;/STRONG&gt; when we execute the query from &lt;STRONG&gt;DBConnect&lt;/STRONG&gt;, where it seems to convert the results returned into epoch format and that is where it seems to be adding an hour. Even when we use DBConnect, the results are fine when we apply the &lt;STRONG&gt;to_char function&lt;/STRONG&gt; on the datetime attribute. For. e.g, select update_time, to_char(update_time,'dd-mon-yyyy hh24:mi:ss') from tablename      returns the string representation of the attribute perfectly fine, but adds one hour to the first column (epoch format) and this addition is only happening on the integration server.&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Swati&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-same-timestamp-getting-indexed-differently-in-two/m-p/146380#M29819</guid>
      <dc:creator>SwatiApte</dc:creator>
      <dc:date>2020-09-28T20:20:06Z</dc:date>
    </item>
  </channel>
</rss>

