<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB Connect 1: Why is the timezone not appearing correctly? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195838#M98672</link>
    <description>&lt;P&gt;I set the TZ=GMT in the DBX app on the search head not the indexers.  So I should set the TZ=GMT on the indexers /opt/splunk/etc/system/local/props.conf as well?  As none of them currently have a TZ set in that locatoin&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2015 20:34:02 GMT</pubDate>
    <dc:creator>edwardrose</dc:creator>
    <dc:date>2015-07-09T20:34:02Z</dc:date>
    <item>
      <title>DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195832#M98666</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;

&lt;P&gt;I have an issue with the TZ not appearing correctly.  I have two different inputs coming in and both have the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[root@splk-srch-01 local]# more props.conf 
[event_data]
TZ = GMT

[user_data]
TZ = GMT
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So any searches within the last hour compared to all time seem to be correct for sourcetype event_data.  But if you do the same searches for user_data the time stamps seem wrong.  &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/43145-last24hrssearch.png" alt="Last 24 hours search" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/43146-alltimesearch.png" alt="All Time search" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195832#M98666</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2020-09-29T06:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195833#M98667</link>
      <description>&lt;P&gt;What is the output of this search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=lenel | dedup date_zone splunk_server index host source | eval lagSecs=_time-_indextime | convert ctime(_indextime) as indextime| table _time indextime lagSecs date_zone splunk_server index host source
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 Jul 2015 17:05:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195833#M98667</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-08T17:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195834#M98668</link>
      <description>&lt;PRE&gt;&lt;CODE&gt; 100 Per Page Format  Preview
_time   indextime   lagSecs date_zone   splunk_server   index   host    source
2015-07-08 17:29:44 07/08/2015 10:29:50 25194.000   0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-07-08 17:29:04 07/08/2015 10:29:10 25194.000   0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-07-08 17:28:18 07/08/2015 10:28:20 25198.000   0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-07-08 10:38:05 07/08/2015 10:38:11 -6  0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView
2015-07-08 10:37:48 07/08/2015 10:37:51 -3  0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView
2015-07-08 10:36:30 07/08/2015 10:36:40 -10 0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView
2015-06-17 14:00:18 06/18/2015 10:14:30 -72852  0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.eventsview
2015-06-17 13:28:54 06/18/2015 10:12:57 -74643  0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.eventsview
2015-06-17 13:13:59 06/18/2015 10:14:57 -75658  0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.eventsview
2015-06-17 00:00:00 06/17/2015 10:30:37 -37837  local   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-06-17 00:00:00 06/17/2015 10:49:26 -38966  local   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 Jul 2015 18:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195834#M98668</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-07-08T18:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195835#M98669</link>
      <description>&lt;P&gt;I assume that all the "account" sources are &lt;CODE&gt;sourcetype=user_data&lt;/CODE&gt; and all the "event" sources are &lt;CODE&gt;sourcetype=event_data&lt;/CODE&gt;.  This is a mess.  To answer just your first question, the search results are showing me that indexers &lt;CODE&gt;splk-idx-03.wv.mentorg.com&lt;/CODE&gt; and &lt;CODE&gt;splk-idx-01.wv.mentorg.com&lt;/CODE&gt; are not using the &lt;CODE&gt;GMT&lt;/CODE&gt; setting so either the file did not go out to them or they have not been restarted.  I know this because instead of &lt;CODE&gt;0&lt;/CODE&gt;, I see &lt;CODE&gt;local&lt;/CODE&gt; for &lt;CODE&gt;date_zone&lt;/CODE&gt; so that is the first thing to fix.  However, all the values of &lt;CODE&gt;lagSecs&lt;/CODE&gt; which are negative indicate a major timestamping problem because these are being indexed as "happened in the future" which is impossible.  This second problem is what is really causing you to misinterpret the first problem.  Because your misconfigurations (some of which still exist) have thrust so many events "to the future", when you search for "last 15 minutes", you are not only seeing events that you have recently indexed, but you are also seeing events from a long time back that were mis-timestamped (and used the wrong TZ) that are just now coming into focus as "now".  So you will have to readjust your methods of analyzing the impact of your configuration changes until all of the "future" data ages out.  Run this search again but do it for "All Time" (I forgot to mention that part) and I can give you a better assessment.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2015 18:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195835#M98669</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-08T18:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195836#M98670</link>
      <description>&lt;P&gt;The output that I put up yesterday was for all time.  Are you suggesting that I change the TZ on all the indexers to use GMT?&lt;/P&gt;

&lt;P&gt;-ed&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 20:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195836#M98670</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-07-09T20:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195837#M98671</link>
      <description>&lt;P&gt;Did you fix the &lt;CODE&gt;TZ=GMT&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt; on the 1 indexers and restart them?  That is the first step but you have &lt;EM&gt;many&lt;/EM&gt; more problems than that.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 20:28:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195837#M98671</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-09T20:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195838#M98672</link>
      <description>&lt;P&gt;I set the TZ=GMT in the DBX app on the search head not the indexers.  So I should set the TZ=GMT on the indexers /opt/splunk/etc/system/local/props.conf as well?  As none of them currently have a TZ set in that locatoin&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 20:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195838#M98672</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-07-09T20:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195839#M98673</link>
      <description>&lt;P&gt;Yes, definitely.  The search results are definitive: you must make this change but it won't fix all of your problems.  It will fix all of the problems that you noticed.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 20:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195839#M98673</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-09T20:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195840#M98674</link>
      <description>&lt;P&gt;Here is from the last 24 hrs&lt;/P&gt;

&lt;P&gt;2015-07-09 13:31:51 07/09/2015 13:31:53 -2  0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView&lt;BR /&gt;
2015-07-09 13:31:26 07/09/2015 06:31:28 25198.000   0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView&lt;BR /&gt;
2015-07-09 13:31:19 07/09/2015 13:31:21 -2  0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView&lt;BR /&gt;
2015-07-09 13:30:49 07/09/2015 06:30:58 25191.000   0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView&lt;BR /&gt;
2015-07-09 13:28:22 07/09/2015 13:28:23 -1  0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView&lt;BR /&gt;
2015-07-09 13:27:14 07/09/2015 06:27:17 25197.000   0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195840#M98674</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2020-09-29T06:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195841#M98675</link>
      <description>&lt;P&gt;Sorry about the long delay but I can report back that I made the change to the TZ  on the indexers and it still did not resolve the issue.  &lt;/P&gt;

&lt;P&gt;Here are the results for the search from AllTime&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_time   indextime   lagSecs date_zone   splunk_server   index   host    source
2015-07-22 15:10:34 07/22/2015 08:10:44 25190.000   0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-07-22 15:09:08 07/22/2015 08:09:14 25194.000   0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-07-22 14:56:31 07/22/2015 07:56:39 25192.000   0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.AccountTransactionsView
2015-07-22 08:12:43 07/22/2015 08:12:50 -7  0   splk-idx-01.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView
2015-07-22 08:12:16 07/22/2015 08:12:18 -2  0   splk-idx-02.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView
2015-07-22 08:11:09 07/22/2015 08:11:15 -6  0   splk-idx-03.wv.mentorg.com  lenel   svr-sql-lnl-11  dbmon-tail://Lenel_OnGuard/dbo.EventsView
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It seems better as the datezone now all show 0 but the time lag is still negative for the sourcetype=event_data.  Which tells me that the DB is probably causing the time issue that we are seeing.  &lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 15:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195841#M98675</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-07-22T15:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect 1: Why is the timezone not appearing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195842#M98676</link>
      <description>&lt;P&gt;Now that &lt;CODE&gt;date_zone&lt;/CODE&gt; is &lt;CODE&gt;0&lt;/CODE&gt;, you know that the TZ portion of your problem is fixed (Splunk is treating the times as being in GMT=UTC).  Since the lag is still negative, &lt;EM&gt;EITHER&lt;/EM&gt; the clock on your Indexers is wrong (it is putting a bad value into &lt;CODE&gt;_indextime&lt;/CODE&gt;) &lt;EM&gt;OR&lt;/EM&gt; the thing generating the timestamps in your DB is wrong.  Don't forget to "Accept" an answer to close this question.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2015 01:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DB-Connect-1-Why-is-the-timezone-not-appearing-correctly/m-p/195842#M98676</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-29T01:33:27Z</dc:date>
    </item>
  </channel>
</rss>

