<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk not picking up on timezone set within props in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/524319#M88520</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50601"&gt;@DEAD_BEEF&lt;/a&gt;&amp;nbsp; Here is a way to re-iterate over the props.conf, basically addressing the same issue you've raised:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/how-make-splunk-heavy-forwarder-reiterate-over-after-changing-efi/?trackingId=ppRO1LfrmMWuu8U5BCTzdA%3D%3D " target="_self"&gt;https://www.linkedin.com/pulse/how-make-splunk-heavy-forwarder-reiterate-over-after-changing-efi/?trackingId=ppRO1LfrmMWuu8U5BCTzdA%3D%3D &lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 05:17:23 GMT</pubDate>
    <dc:creator>efika</dc:creator>
    <dc:date>2020-10-13T05:17:23Z</dc:date>
    <item>
      <title>Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408968#M72513</link>
      <description>&lt;P&gt;Hi everyone.  I have logs that are sent to me in Central Standard Time (-6 hours) but there isn't anything in the TA noting that, so all my logs look like they are 6 hours behind.&lt;/P&gt;

&lt;P&gt;As such, I went in and added a props.conf in &lt;CODE&gt;local&lt;/CODE&gt; with the statement&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[infoblox:dhcp]
TZ = CST
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Pushed the updated TA through the cluster bundle on my cluster master to all indexers and verified they all received the updated TA.  Looking at my latest logs (about 30 afterwards) I still see the latest logs showing up as 6 hours behind (no change).  I ran btool to see which props settings were being picked up by the app and indeed it shows it there.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;/opt/splunk/bin/splunk cmd btool --app=Splunk_TA_infoblox props list&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[infoblox:dhcp]
EVAL-...
EXTRACT-...
TZ = CST
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas?  I feel like I'm overlooking something obvious.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 22:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408968#M72513</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-17T22:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408969#M72514</link>
      <description>&lt;P&gt;Based on my searching last year - &lt;A href="https://answers.splunk.com/answers/617776/what-is-the-tz-for-america-central.html"&gt;What is the TZ for America Central?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;TZ=US/Central&lt;/CODE&gt; seems to be deprecated and it should be &lt;CODE&gt;TZ=America/Chicago&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 23:21:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408969#M72514</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2019-01-17T23:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408970#M72515</link>
      <description>&lt;P&gt;I changed it to what you have, repushed and it's showing up in btool.  Unfortunately, logs are still showing up "6 hours behind"  I appreciate the info on the deprecated naming scheme though!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 00:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408970#M72515</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T00:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408971#M72516</link>
      <description>&lt;P&gt;Try  the following format&lt;/P&gt;

&lt;P&gt;TZ = CST&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 01:39:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408971#M72516</guid>
      <dc:creator>hdbang_splunk</dc:creator>
      <dc:date>2019-01-18T01:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408972#M72517</link>
      <description>&lt;P&gt;The precedence for TZ is:&lt;BR /&gt;
1: If &lt;CODE&gt;%z&lt;/CODE&gt; is configured in &lt;CODE&gt;TIME_FORMAT&lt;/CODE&gt; and is in the event use that &lt;EM&gt;EXCEPT&lt;/EM&gt;...&lt;BR /&gt;
0: If this matches a &lt;CODE&gt;TZ_ALIAS&lt;/CODE&gt; setting, override with that.&lt;BR /&gt;
2: If the forwarder has a &lt;CODE&gt;TZ&lt;/CODE&gt; setting, use that.&lt;BR /&gt;
3: If the indexer has a &lt;CODE&gt;TZ&lt;/CODE&gt; setting, use that.&lt;BR /&gt;
4: Use the TZ that is configured in the host OS of the indexer (which could be different on every indexer).&lt;/P&gt;

&lt;P&gt;You can get some hits as to what has happened for your event by checking the &lt;CODE&gt;date_zone&lt;/CODE&gt; field.&lt;/P&gt;

&lt;P&gt;Much of the time the &lt;EM&gt;actual&lt;/EM&gt; problem is that you are not testing your configuration changes properly so BE ABSOLUTELY SURE that:&lt;BR /&gt;
1: You restart the splunk service on any device where you deploy a configuration.&lt;BR /&gt;
2: Add &lt;CODE&gt;_index_earliest=-1m&lt;/CODE&gt; to your search to make absolutely certain that you are looking ONLY at events that were recently indexed.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 01:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408972#M72517</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T01:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408973#M72518</link>
      <description>&lt;P&gt;Hi @woodcock!&lt;/P&gt;

&lt;P&gt;1:  No &lt;CODE&gt;TIME_FORMAT&lt;/CODE&gt;&lt;BR /&gt;
0:  No &lt;CODE&gt;TZ_ALIAS&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;If I use the TZ that is configured in the indexer (3) or OS (4), wouldn't that set TZ = GMT since both my indexer and the OS is running in GMT?  These logs are coming in as CST.  I'm sorry I don't understand these suggestions.&lt;/P&gt;

&lt;P&gt;I didn't restart the splunk service because when I did &lt;CODE&gt;--check-restart&lt;/CODE&gt; it said restart is not required since I am only adding a new &lt;CODE&gt;props.conf&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Tried using &lt;CODE&gt;_index_earliest=-1m&lt;/CODE&gt; and no results.  Neat command!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 02:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408973#M72518</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T02:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408974#M72519</link>
      <description>&lt;P&gt;The TZ is set at indextime and is immutable after that.  Your &lt;CODE&gt;TZ&lt;/CODE&gt; configuration changes will never effect already-indexed data (which is why I mentioned that your testing assumptions are probably where the problem is).  You must send NEW data in to see if your new settings work.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 04:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408974#M72519</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T04:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408975#M72520</link>
      <description>&lt;P&gt;How are the logs coming in to your indexers? Is there a heavy forwarder involved by any chance?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:20:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408975#M72520</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-01-18T07:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408976#M72521</link>
      <description>&lt;P&gt;Logs are being sent to a syslog server, UF running on that sending it to the indexers.  Splunk TA is then on the indexer doing the magic.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 13:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408976#M72521</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T13:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408977#M72522</link>
      <description>&lt;P&gt;I'm getting new data in constantly.  Are you saying that the new data won't have the new props TZ applied to it for some reason?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 14:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408977#M72522</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T14:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408978#M72523</link>
      <description>&lt;P&gt;I am saying if something like &lt;CODE&gt;_index_earliest=-1m&lt;/CODE&gt; and a timepicker of &lt;CODE&gt;All time&lt;/CODE&gt; returns no events, then you are not getting new events all the time.  Did you use &lt;CODE&gt;All time&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408978#M72523</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T15:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408979#M72524</link>
      <description>&lt;P&gt;What he is using should work, but I agree with this.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408979#M72524</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T15:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408980#M72525</link>
      <description>&lt;P&gt;Updated it to your suggestions, but events are still showing up as 6 hours behind.  I haven't done a rolling restart as &lt;CODE&gt;--check-restart&lt;/CODE&gt; said it is not required, but at this point I'm not sure what else to try.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408980#M72525</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T15:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408981#M72526</link>
      <description>&lt;P&gt;@woodcock okay, sorry for my confusion.  I ran &lt;CODE&gt;_index_earliest=-1m&lt;/CODE&gt; for all time and it is showing new events that are "6 hours behind".  I refreshed it a few times and verified that the event count is increasing and getting newer timestamped events.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408981#M72526</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T15:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408982#M72527</link>
      <description>&lt;P&gt;Run this command on your indexers:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk btool props list --debug | less
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It should help pinpoint what value is being used AND FROM WHAT FILE.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 16:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408982#M72527</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T16:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408983#M72528</link>
      <description>&lt;P&gt;from running the command I found this in the output:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/$splunk_home$/Splunk_TA_infoblox/local/props.conf   TZ = CST
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 18 Jan 2019 16:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408983#M72528</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T16:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408984#M72529</link>
      <description>&lt;P&gt;That is the only output for &lt;CODE&gt;TZ&lt;/CODE&gt;?  That is way unexpected.&lt;/P&gt;

&lt;P&gt;Are you using &lt;CODE&gt;INDEXED_EXTRACTIONS&lt;/CODE&gt; or Heavy Forwarders on this input?&lt;BR /&gt;
If the former, this setting needs to be on the UF, if the latter, this setting needs to be on the HFs.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 16:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408984#M72529</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T16:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408985#M72530</link>
      <description>&lt;P&gt;It was the only TZ for that app.  there were other hits for &lt;CODE&gt;TZ&lt;/CODE&gt; but they were all in other apps on the indexer (none in /etc/system/default or /etc/system/local).&lt;/P&gt;

&lt;P&gt;This is an indexer with the Splunk TA running.  The sourcetype is named via a transforms, and then I am calling that name in props for the TZ fix.  No &lt;CODE&gt;INDEXED_EXTRACTIONS&lt;/CODE&gt;, the data is coming in via .log files from a UF.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 17:27:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408985#M72530</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2019-01-18T17:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408986#M72531</link>
      <description>&lt;P&gt;It doesn't matter what app it is in, it matters what sourcetype it is applied to.  In any case, try sending the props.conf to the UF and BE SURE that the &lt;CODE&gt;sourcetype&lt;/CODE&gt; value for this setting (regardless of what app contains it) matches your data.  I suspect that this is your problem.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 17:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408986#M72531</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-18T17:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not picking up on timezone set within props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408987#M72532</link>
      <description>&lt;P&gt;At this point, I would go over to the universal forwarders and check how the timestamp is generated (is it in the . format?) and any timezone settings there, including timezone setting of the OS.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 18:08:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-picking-up-on-timezone-set-within-props/m-p/408987#M72532</guid>
      <dc:creator>arkadyz1</dc:creator>
      <dc:date>2019-01-18T18:08:08Z</dc:date>
    </item>
  </channel>
</rss>

