Getting Data In
Highlighted

Checkpoint logs being indexed incorrectly ( One hour earlier )

Explorer

I am having trouble with my checkpoint log.
Or indefinite is late hour.

Example:
Actual time of the event: 12:15.
Time that is indexed on spunk: 11:15: AM

Time at checkpoint is correct. Splunk time is ticking. Already added in props.conf the checkpoing or sourcetype [opsec] and put the parameter
TZ = America / Sao_Paulo, but I have the wrong indexing

0 Karma
Highlighted

Re: Checkpoint logs being indexed incorrectly ( One hour earlier )

Motivator

The past weekend was daylight savings changeover. Are you certain all your timezones are set properly? Is the clock on the indexer(s) accurate?

Cheers,
Jacob
Highlighted

Re: Checkpoint logs being indexed incorrectly ( One hour earlier )

Explorer

Hi Jacob.
Yes. I'm check all indexers.

0 Karma
Highlighted

Re: Checkpoint logs being indexed incorrectly ( One hour earlier )

SplunkTrust
SplunkTrust

Where have you put the props.conf for TZ setting for opsec sourcetype, Indexer/Intermediate Forwarder OR at universal forwarder where you're monitoring the log file?

Highlighted

Re: Checkpoint logs being indexed incorrectly ( One hour earlier )

Explorer

A TZ configuration was used in the indexer. This server has the OPSEC LEA app and all configuration is all made on it.

0 Karma