<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk search issues with timezone of logs from forwarders in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413088#M119113</link>
    <description>&lt;P&gt;Forwarder is on Windows server and splunk enterprise is on RHEL 6.1.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2019 16:12:04 GMT</pubDate>
    <dc:creator>rchittip</dc:creator>
    <dc:date>2019-06-11T16:12:04Z</dc:date>
    <item>
      <title>Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413085#M119110</link>
      <description>&lt;P&gt;Dears, &lt;/P&gt;

&lt;P&gt;My Splunk Indexer is in CDT time zone and my forwarder logs are in UTC time zone and there is time difference of 5hrs. When I do the search in my splunk search head, data is getting indexed with 5 hour difference with the current time of splunk indexer. &lt;/P&gt;

&lt;P&gt;Below are the forwarder logs: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2019-06-11 12:50:42 10.100.4.65 GET /Test/GetStoreItemInv/1111/000000/username/ - 9988 - 10.111.195.0 okhttp/2.6.0 - 200 0 0 531 
2019-06-11 12:50:42 10.100.4.65 GET /Test/GetStoreItemInv/0910/2882183/username/ - 9988 - 10.111.195.0 okhttp/2.6.0 - 200 0 0 515 
2019-06-11 12:50:42 10.100.4.65 GET /Test/GetStoreItemInv/2237/0544067/username/ - 9988 - 10.111.195.0 okhttp/2.6.0 - 200 0 0 578 
2019-06-11 12:50:42 10.100.4.65 GET /ITest/GetStoreItemInv/2086/8513336/username/ - 9988 - 10.111.195.0 okhttp/2.6.0 - 200 0 0 671 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I had updated the below stanza in on my forwarder /etc/system/loca/props.conf file but still nothing seems to be worked. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ItmInqWebServiceWeb] 
TZ = America/Chicago 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For time being, every time I search I'm adding  &lt;CODE&gt;"latest=+5h earliest=+45m"&lt;/CODE&gt; with my search. &lt;/P&gt;

&lt;P&gt;Do I also need to update the above stanza in indexer server props.conf as well?&lt;/P&gt;

&lt;P&gt;Thanks, &lt;BR /&gt;
Ramu Chittiprolu &lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413085#M119110</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2019-06-11T15:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413086#M119111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;TZ have to be set at parsing time - which means it will not work on universal forwarder. Set the setting on your indexers or intermediate heavy forwarders and it will fix you issue.&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;/P&gt;

&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:26:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413086#M119111</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2019-06-11T15:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413087#M119112</link>
      <description>&lt;P&gt;Are you running Forwarder on RedHat Linux ? If yes then is it RHEL 6 or RHEL 7 ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413087#M119112</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-06-11T15:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413088#M119113</link>
      <description>&lt;P&gt;Forwarder is on Windows server and splunk enterprise is on RHEL 6.1.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413088#M119113</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2019-06-11T16:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413089#M119114</link>
      <description>&lt;P&gt;Have you tried with &lt;CODE&gt;TZ=CDT&lt;/CODE&gt; on Forwarder ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413089#M119114</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-06-11T16:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413090#M119115</link>
      <description>&lt;P&gt;Yes, I tried below two in props.conf individually and restarted the forwarder but still search results are not correct.&lt;/P&gt;

&lt;P&gt;[ItmInqWebServiceWeb] &lt;BR /&gt;
TZ=CDT &lt;/P&gt;

&lt;P&gt;[ItmInqWebServiceWeb] &lt;BR /&gt;
TZ = America/Chicago&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:30:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413090#M119115</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2019-06-11T16:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413091#M119116</link>
      <description>&lt;P&gt;When you change timezone config on forwarder, it will apply to only new data. Data which is already ingested will not change with new timezone setting.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:32:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413091#M119116</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-06-11T16:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413092#M119117</link>
      <description>&lt;P&gt;yes, I have the latest logs updated on the forwarder end but still no luck. Do I also need to update the TZ entry for sourcetype in indexer server as well ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:43:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413092#M119117</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2019-06-11T16:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413093#M119118</link>
      <description>&lt;P&gt;As far as I know, if you are running Forwarder and Indexer version 6.0+ then TZ on forwarder should work.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 08:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413093#M119118</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-06-12T08:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search issues with timezone of logs from forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413094#M119119</link>
      <description>&lt;P&gt;My forwarder and splunk version is 6.6.3. Not sure why this is not working.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 09:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-issues-with-timezone-of-logs-from-forwarders/m-p/413094#M119119</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2019-06-12T09:09:19Z</dc:date>
    </item>
  </channel>
</rss>

