Deployment Architecture

TZ (timezone) -- where do I set it in a clustered environment?

dpanych
Communicator

Hello, we have a syslog device that is sending log in UTC, but we need them to be in US/Pacific. Where do I set the TZ setting? Searchhead? Indexers? HeavyForwarder?

0 Karma
1 Solution

ryandg
Communicator

If the data is being received at the HeavyForwarder then set it at the HF, if the data is going straight to the indexers set at the indexers. Never the searchhead.

View solution in original post

wagnerbianchi
Splunk Employee
Splunk Employee
0 Karma

ryandg
Communicator

If the data is being received at the HeavyForwarder then set it at the HF, if the data is going straight to the indexers set at the indexers. Never the searchhead.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...