We are using Splunk DB Connect v1 where we have 2 servers in different data centers (one in Eastern Timezone and another one in Central Timezone). In both the servers we have props.conf configured to use TZ/Central and the cron job for database query execution is set to
0 5 * * *. We are expecting both the servers to run query exactly at 5 am Central Time, which works fine for the server in Central Timezone however it runs one hour earlier for the server in Eastern Timezone. It appears that the server in Eastern Timezone is neglecting props.conf file and using the system/OS timezone.
In addition to this, we are also seeing timestamp issues in the manual query execution results for the timestamp columns, that is running an hour ahead of Central Time.
Would you please let us know how to fix these issues? Does the system/OS time needs to be updated or is there anything other than props.conf file to enter the timezone which can be referred by all the input cron jobs and manual query executions?
Thank you jcoates. So what do you suggest if we have DB Connect servers in various timezones. Should we update the system time to run all in the same timezone or is there anything from the Splunk software (or DB connect app) that we can adjust to let all DB Connect servers behave same no matter which timezone they are hosted?