All Apps and Add-ons

Does Splunk DB Connect cron frequency for query execution uses system time or the timezone listed in props.conf?

ash2l
Path Finder

We are using Splunk DB Connect v1 where we have 2 servers in different data centers (one in Eastern Timezone and another one in Central Timezone). In both the servers we have props.conf configured to use TZ/Central and the cron job for database query execution is set to 0 5 * * *. We are expecting both the servers to run query exactly at 5 am Central Time, which works fine for the server in Central Timezone however it runs one hour earlier for the server in Eastern Timezone. It appears that the server in Eastern Timezone is neglecting props.conf file and using the system/OS timezone.

In addition to this, we are also seeing timestamp issues in the manual query execution results for the timestamp columns, that is running an hour ahead of Central Time.

Would you please let us know how to fix these issues? Does the system/OS time needs to be updated or is there anything other than props.conf file to enter the timezone which can be referred by all the input cron jobs and manual query executions?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

It uses system time.

0 Karma

ash2l
Path Finder

Thank you jcoates. So what do you suggest if we have DB Connect servers in various timezones. Should we update the system time to run all in the same timezone or is there anything from the Splunk software (or DB connect app) that we can adjust to let all DB Connect servers behave same no matter which timezone they are hosted?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...