<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355783#M65021</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/180565"&gt;@mwdbhyat&lt;/a&gt;&lt;/P&gt;

&lt;P&gt;I changed these two values in inputs.conf &lt;/P&gt;

&lt;P&gt;start_from = newest&lt;BR /&gt;
current_only = 1&lt;/P&gt;

&lt;P&gt;and it resolved my issue THANK YOUUUUU SO MUCH MAN! for some reason i dont see your comment here can you please paste it again I want to mark that as accepted answer.&lt;/P&gt;

&lt;P&gt;Thanks once again&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:55:49 GMT</pubDate>
    <dc:creator>hrithiktej</dc:creator>
    <dc:date>2020-09-29T15:55:49Z</dc:date>
    <item>
      <title>Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355765#M65003</link>
      <description>&lt;P&gt;In our Slave-Apps directory on the 2 peers/indexers we have a custom app created by the prev admin which has setting for TZ to UTC for network devices that are on UTC. Now i am adding new data source (i.e. AD security logs) using UFs on DCs and our DCs are all in EST TZ and hence i would need to list EST TZ in the props.conf. &lt;/P&gt;

&lt;P&gt;My Questions are&lt;/P&gt;

&lt;P&gt;1) Is this the right stanza for EST time entry&lt;BR /&gt;
[WinEventLog://Security]&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;I understand i will have to do this on master-apps folder on cluster master and then apply config bundle&lt;/P&gt;

&lt;P&gt;2) Will this require a reboot of any peers ?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 18:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355765#M65003</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-22T18:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355766#M65004</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;1 - Yes thats correct&lt;/P&gt;

&lt;P&gt;2 - Yes, the cluster master will initiate a restart of its cluster members once you apply the new cluster bundle. Please see here for what requires a restart and what doesnt..&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Updatepeerconfigurations#Restart_or_reload_after_configuration_bundle_changes.3F"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Updatepeerconfigurations#Restart_or_reload_after_configuration_bundle_changes.3F&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 19:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355766#M65004</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2017-09-22T19:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355767#M65005</link>
      <description>&lt;P&gt;Are you sure the time zone is right? or should it be EST?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 15:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355767#M65005</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-23T15:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355768#M65006</link>
      <description>&lt;P&gt;Sure am:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Propsconf&lt;/A&gt;  --search for "The following example sets Eastern Time Zone"&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 16:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355768#M65006</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2017-09-23T16:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355769#M65007</link>
      <description>&lt;P&gt;This is my props.conf on indexers&lt;/P&gt;

&lt;P&gt;[cisco:asa]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[cisco:ise:syslog]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[cisco:acs]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[cisco:ios]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[cisco:sourcefire]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[f5:bigip:syslog]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[pan:log]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;[catchall:catchall]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;it is not working for events that are coming for [WinEventLog://Security] because if i search for last 15mins or 60 mins i dont get results ONLY when i select last 4hours i can see results. I also tried switching my user time zone from UTC to EST through settings&amp;gt;users&amp;gt;my user timezone as EST and log out/login but still the same issue.&lt;/P&gt;

&lt;P&gt;And I have installed Splunk_TA_windows on my UF that sits on DC&lt;/P&gt;

&lt;P&gt;Any help will be appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355769#M65007</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2020-09-29T15:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355770#M65008</link>
      <description>&lt;P&gt;Ok yeah i see that but its not working for medid u see my props.conf in the below comment and also i am defining TZ by sourcetype and not host will that make a difference ?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 18:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355770#M65008</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-23T18:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355771#M65009</link>
      <description>&lt;P&gt;I tried with host entry as well it did not work , still when i go to last 4hrs only then i can see events otherwise in realtime search or last 15 or 60mins it does not show up&lt;/P&gt;

&lt;P&gt;[host::dc1-corpdc01]&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 19:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355771#M65009</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-23T19:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355772#M65010</link>
      <description>&lt;P&gt;What happens if you dont apply a TZ ? What time are you getting for your sourcetype then?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 08:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355772#M65010</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2017-09-24T08:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355773#M65011</link>
      <description>&lt;P&gt;Same. I did not apply a TZ before only when this issue started i realised i should enter TZ in props.conf and entering did not make a difference. I also tried entering TZ by creating a props.conf in UFs local but no joy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 08:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355773#M65011</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-24T08:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355774#M65012</link>
      <description>&lt;P&gt;Can you send me an example of the search you are running and a snip of the results? &lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 10:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355774#M65012</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2017-09-24T10:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355775#M65013</link>
      <description>&lt;P&gt;I am simply typing  sourcetype="WinEventLog:Security"  in search and i do not find anything when i do last15mins or 60 mins i can only see for last 4hrs and event time is real time like if you convert from UTC to IST (which is the TZ I live in).&lt;/P&gt;

&lt;P&gt;Also it does not allow me here to paste an image only an url&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 10:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355775#M65013</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2017-09-24T10:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355776#M65014</link>
      <description>&lt;P&gt;Check if there is some kind of indexing lag in your environment -&lt;/P&gt;

&lt;P&gt;source=mysource | eval delay_sec=_indextime-_time | timechart min(delay_sec) avg(delay_sec) max(delay_sec) by host&lt;/P&gt;

&lt;P&gt;Alternatively - has that DC host been set a timezone in another app? Can you run a btool to check that?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355776#M65014</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2020-09-29T15:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355777#M65015</link>
      <description>&lt;P&gt;Use this search to verify the source type, the time stamp detected (_time), the time of the user on the search head (now), and the time zone applied (date_zone)&lt;/P&gt;

&lt;P&gt;source=mysource host=myhost | eval delay_sec=_indextime-_time | convert ctime(_indextime) AS indextime | eval now=now() | table _time indextime now date_zone source sourcetype host&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:51:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355777#M65015</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2020-09-29T15:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355778#M65016</link>
      <description>&lt;P&gt;Thanks, I ran the queries and below are the results, there seems to be a 3-4hrs delay and time diff I do not know why, if I run these queries for other sources it does not show any delay or time difference.&lt;/P&gt;

&lt;P&gt;source=mysource | eval delay_sec=_indextime-_time | timechart min(delay_sec) avg(delay_sec) max(delay_sec) by host&lt;/P&gt;

&lt;P&gt;_time&lt;BR /&gt;&lt;BR /&gt;
2017-09-25 06:45:00&lt;/P&gt;

&lt;P&gt;avg(delay_sec)&lt;BR /&gt;&lt;BR /&gt;
 8618                           &lt;/P&gt;

&lt;P&gt;max(delay_sec) &lt;BR /&gt;
 8656&lt;/P&gt;

&lt;P&gt;min(delay_sec)&lt;BR /&gt;
8593&lt;/P&gt;

&lt;P&gt;source=mysource host=myhost | eval delay_sec=_indextime-_time | convert ctime(_indextime) AS indextime | eval now=now() | table _time indextime now date_zone source sourcetype host&lt;/P&gt;

&lt;P&gt;_time&lt;BR /&gt;&lt;BR /&gt;
2017-09-25 06:59:30     &lt;/P&gt;

&lt;P&gt;indextime&lt;BR /&gt;&lt;BR /&gt;
 09/25/2017 09:16:39&lt;/P&gt;

&lt;P&gt;source&lt;BR /&gt;&lt;BR /&gt;
WinEventLog:Security   &lt;/P&gt;

&lt;P&gt;Also please note to troubleshoot this now I have changed the timezone for all my Splunk servers to match with my Domain controller so now both indexer and source have same TZ = EST but still I am not able to search logs in last 60mins or 15mins.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355778#M65016</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2020-09-29T15:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355779#M65017</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/51116"&gt;@hrithiktej&lt;/a&gt;&lt;/P&gt;

&lt;P&gt;props.conf seems correct.&lt;/P&gt;

&lt;P&gt;[host::yourhostdefinition]&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;P&gt;[source::yousourcedefinition]&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;or&lt;BR /&gt;
[yoursourcetypedefinition]&lt;BR /&gt;
TZ = US/Eastern&lt;/P&gt;

&lt;P&gt;Can you please check path of the props.conf and check it has enough permission for splunk to read.&lt;/P&gt;

&lt;P&gt;CM - $SPLUNK_HOME$/etc/master-apps/_cluster/local/props.conf --- use this location if you don't have separate app.&lt;BR /&gt;
CM - $SPLUNK_HOME$/etc/master-apps/your app/local/props.conf -- use this location if you have separate app for it.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:55:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355779#M65017</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2020-09-29T15:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355780#M65018</link>
      <description>&lt;P&gt;Can you send a snip of your input stanza for the security logs in wineventlog ? &lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 14:16:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355780#M65018</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2017-09-25T14:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355781#M65019</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/180565"&gt;@mwdbhyat&lt;/a&gt;&lt;/P&gt;

&lt;P&gt;I see your comment in email notification but not here.&lt;/P&gt;

&lt;P&gt;And this is my inputs I am using the default inputs.conf from the Splunk_TA_Windows app.&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;
blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;
index = wineventlog&lt;BR /&gt;
renderXml=false&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355781#M65019</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2020-09-29T15:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355782#M65020</link>
      <description>&lt;P&gt;You should make changes in the local folder, just in case someone comes along and creates a stanza for the same sourcetype and overwrites your settings in default(it wont fix your problem but is a best practice).&lt;/P&gt;

&lt;P&gt;Regarding you inputs it looks fine - but there is clearly a lag in indexing.. Can your environment handle the amount of data that is flowing into your indexers from wineventlog?&lt;/P&gt;

&lt;P&gt;This article has a few tricks you can try:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.3/Troubleshooting/Troubleshootingeventsindexingdelay"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.3/Troubleshooting/Troubleshootingeventsindexingdelay&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 14:30:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355782#M65020</guid>
      <dc:creator>mwdbhyat</dc:creator>
      <dc:date>2017-09-25T14:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355783#M65021</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/180565"&gt;@mwdbhyat&lt;/a&gt;&lt;/P&gt;

&lt;P&gt;I changed these two values in inputs.conf &lt;/P&gt;

&lt;P&gt;start_from = newest&lt;BR /&gt;
current_only = 1&lt;/P&gt;

&lt;P&gt;and it resolved my issue THANK YOUUUUU SO MUCH MAN! for some reason i dont see your comment here can you please paste it again I want to mark that as accepted answer.&lt;/P&gt;

&lt;P&gt;Thanks once again&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355783#M65021</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2020-09-29T15:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf timezone settings for Eastern? And do I need to reboot any peers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355784#M65022</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/55793"&gt;@sbbadri&lt;/a&gt; Thank you fr your reply&lt;/P&gt;

&lt;P&gt;mwdbhyat &lt;BR /&gt;
was very helpful and kind enough to help me so much. This is resolved by changing these two values in my inputs.conf&lt;/P&gt;

&lt;P&gt;start_from = newest&lt;BR /&gt;
current_only = 1&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-timezone-settings-for-Eastern-And-do-I-need-to-reboot/m-p/355784#M65022</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2020-09-29T15:55:52Z</dc:date>
    </item>
  </channel>
</rss>

