All Apps and Add-ons

Specifying timezone in props.conf of Add-On is not working

ezmo1982
Path Finder

Hi, 

I am using the Solarwinds Add-on. I have it installed on my HF and it is working fine. However there is one sourcetype (out of the 3) which the timestamp is not correct - it is named "solarwinds:alerts". It appears to be one hour behind the other sourcetypes. It looks to be GMT when it should be GMT+1.

I have created a new props.conf file in /etc/splunk/apps/Splunk_TA_Solarwinds/local/ directory of the HF instance . In this file I have added:

[sourcetype::"solarwinds:alerts"]                                                                                                                                                      TZ = GMT+1

I saved the config, restarted the HF and search for the events of this sourcetype but they still appear to be off by one hour and the TZ setting doesnt seem to be working.

Researching online, this seems to be the standard way to set a timezone. Is there something I am doing wrong?

Thanks!

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You probably are fitted by summertime definition which is not known if you are using GMT as TZ. Here is some explanation of it https://community.splunk.com/t5/Getting-Data-In/Setting-other-TZ-in-props-conf/m-p/38984. So try to use those which also contains Summertime information.

r. Ismo

0 Karma

ezmo1982
Path Finder

I have modified props.conf to the below...

[sourcetype::"solarwinds:alerts"]

TZ = UTC

.... but still it has no effect on the timestamps of the events coming in from this sourcetype. i tried multiple different timezone identifiers from https://en.wikipedia.org/wiki/List_of_tz_database_time_zones as a test and none make any difference. 

Something im doing wrong?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Your props.conf definition is on that host where those solarwind files are read?
Can you post you inputs.conf + props.conf and sample of that log?
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...