Getting Data In

Can you help me get data from different time zones into CST time?

snigdhasaxena
Communicator

I have Splunk forwarders using time zone CST while the servers from where forwarders are picking up the data are in EST and GMT time zones.

What should be done to get all the data in CST time zone as used by the Splunk forwarder?

0 Karma
1 Solution

damann
Communicator

When all your forwarded data provide a valid timestamp with additional information of the timezone everything is fine. Splunk recognizes the timezone automatically for you and will adjust the timestamp while indexing.

Another way to make sure your events get indexed properly you should take a look in the props.conf:
https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

There you can specify the correct TZ for a set of servers by using stanzas as you can see in the examples.

View solution in original post

0 Karma

damann
Communicator

When all your forwarded data provide a valid timestamp with additional information of the timezone everything is fine. Splunk recognizes the timezone automatically for you and will adjust the timestamp while indexing.

Another way to make sure your events get indexed properly you should take a look in the props.conf:
https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

There you can specify the correct TZ for a set of servers by using stanzas as you can see in the examples.

0 Karma

dkeck
Influencer

Hi,

I don´t get why you wan´t to change the TZ from EST to CST on the same source, but..

you can set this in props.conf for host or source

https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

valid TZ are listed here : https://en.wikipedia.org/wiki/List_of_tz_database_time_zones

Set this on your Indexer or Heavy Forwarder

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...