<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how does time synchronization work between forwarder and indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305795#M57686</link>
    <description>&lt;P&gt;The Indexers work by doing whatever you tell them to do.  If you tell them nothing about timezones, then each indexer will assume that any event with a date missing a timezone is using the same timezone as that Indexer's host OS and that event will be assigned a value of &lt;CODE&gt;local&lt;/CODE&gt; for &lt;CODE&gt;date_zone&lt;/CODE&gt;.  This is TERRIBLE rookie admin, though; I do not allow events with &lt;CODE&gt;date_zone&lt;/CODE&gt; = &lt;CODE&gt;local&lt;/CODE&gt; to exist on any of my Indexers.  Each event should EITHER have the TZ value inside of each event's timestamp OR each host+sourcetype combination should have a &lt;CODE&gt;TZ=foo/bar&lt;/CODE&gt; in a &lt;CODE&gt;props.conf&lt;/CODE&gt; on every Indexer.  That is the way to do it or you are going to have broken (mis-normalized) times inside of Splunk events (all over the place).&lt;/P&gt;</description>
    <pubDate>Mon, 22 May 2017 17:02:49 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-05-22T17:02:49Z</dc:date>
    <item>
      <title>how does time synchronization work between forwarder and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305793#M57684</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
we have hosts sending logs to indexer using universal forwarders.  The hosts are spread across different time zones. &lt;BR /&gt;
i want to know how the indexer Synchronize different time zones into one. Can you refer any document or something?&lt;/P&gt;

&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 12:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305793#M57684</guid>
      <dc:creator>gnanaraj_mcc</dc:creator>
      <dc:date>2017-05-22T12:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: how does time synchronization work between forwarder and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305794#M57685</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Have you already seen the foillowing answer?&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/52235/if-multiple-hosts-in-different-time-zones-are-sending-logs-to-splunk-in-that-case-how-to-configure-timezone-props-conf-for-the-hosts-individually.html"&gt;https://answers.splunk.com/answers/52235/if-multiple-hosts-in-different-time-zones-are-sending-logs-to-splunk-in-that-case-how-to-configure-timezone-props-conf-for-the-hosts-individually.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Every way the documentation is at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.0/Data/Applytimezoneoffsetstotimestamps"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.0/Data/Applytimezoneoffsetstotimestamps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 13:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305794#M57685</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-05-22T13:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: how does time synchronization work between forwarder and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305795#M57686</link>
      <description>&lt;P&gt;The Indexers work by doing whatever you tell them to do.  If you tell them nothing about timezones, then each indexer will assume that any event with a date missing a timezone is using the same timezone as that Indexer's host OS and that event will be assigned a value of &lt;CODE&gt;local&lt;/CODE&gt; for &lt;CODE&gt;date_zone&lt;/CODE&gt;.  This is TERRIBLE rookie admin, though; I do not allow events with &lt;CODE&gt;date_zone&lt;/CODE&gt; = &lt;CODE&gt;local&lt;/CODE&gt; to exist on any of my Indexers.  Each event should EITHER have the TZ value inside of each event's timestamp OR each host+sourcetype combination should have a &lt;CODE&gt;TZ=foo/bar&lt;/CODE&gt; in a &lt;CODE&gt;props.conf&lt;/CODE&gt; on every Indexer.  That is the way to do it or you are going to have broken (mis-normalized) times inside of Splunk events (all over the place).&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 17:02:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305795#M57686</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-05-22T17:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: how does time synchronization work between forwarder and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305796#M57687</link>
      <description>&lt;P&gt;@woodcock strikes again! FTW!&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 12:19:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305796#M57687</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-05-23T12:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: how does time synchronization work between forwarder and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305797#M57688</link>
      <description>&lt;P&gt;In other words, there is no &lt;CODE&gt;synchronization&lt;/CODE&gt;, there is a &lt;CODE&gt;normalization&lt;/CODE&gt; to &lt;CODE&gt;UTC&lt;/CODE&gt; in the form of &lt;CODE&gt;time_t&lt;/CODE&gt; AKA &lt;CODE&gt;epoch&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 13:39:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-does-time-synchronization-work-between-forwarder-and-indexer/m-p/305797#M57688</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-05-23T13:39:13Z</dc:date>
    </item>
  </channel>
</rss>

