Getting Data In

How can we adjust our firewall's timezone?

Hemnaath
Motivator

Hi All, Currently we are facing an issue with time stamp for an firewall logs. We could see the logs are coming into splunk with a time difference of 3 hours. We have 5 heavy forwarder instance as intermediate forwarder and this firewall log is read from this 5 HF instance which is configured as syslogs server. The splunk reads the logs from these 5 HF instance and then ingest the data into indexer.

inputs.conf detail :
[monitor:///opt/syslogs/mguard/.../mguard.log*]
index=fw
sourcetype=mguard:network:log
host_segment = 4

10/13/17
10:35:57.000 AM
Oct 13 10:35:57 test01.xxx.com 1,2017/10/13 10:35:57,007257000034869,TRAFFIC,start,0,2017/10/13 10:35:57,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-xxxx,,,ssl,vsys1,trust,xxxx,ethernet1/2,ethernet1/1,Splunk,2017/10/13 10:35:57,761997,1,51475,8089,0,0,0x104000,tcp,allow,416,350,66,4,2017/10/13 10:35:56,0,any,0,70021120,0x0,x.0.0.0-x.255.255.255,United States,0,3,1,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A
eventtype = nix-all-logs eventtype = pan network host = test01.xxx.com source = /opt/syslogs/mguard/test01.xxx.com/mguard.log sourcetype = mguard:network:log tag = network timeendpos = 16 timestartpos = 0

Current EDT time is 1:40 PM and logs are coming into splunk with a timestamp of
10:35:57.000 AM, so need to adjust the time zone by 3 hours to match the current EDT time.

Kindly guide me how to adjust this time zone by 3 hours in Splunk

0 Karma
1 Solution

nickhills
Ultra Champion

Your firewall logs don't appear to specify a timezone offset, so Splunk will assume the timestamps are in UTC.

1.) Are you sure your firewall has the correct time?
2.) Does your firewall know what TZ its in?
3.) Can you amend your firewalls logs to include a TZ?
4.) Maybe you can "fix" this on the syslog server? - In my experience its always better to try and fix this as close to the source as possible.

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

Hi @sarwshai - its not about where (in the world) your forwarders are. Its about where your firewall is. The reason for this, is that we should assume that the time on the firewall is right... That is to say, a fw in the UK will use UK time, and one in Sydney is in AEST. That's why you need to set your sourcetype to use the TZ of the source data.
So. the first question is therefore "where is your firewall located?"

If my comment helps, please give it a thumbs up!
0 Karma

Hemnaath
Motivator

Hi Nickhillscpl, thanks a lot, issue seems to be fixed, now we could see the index time is matching the current time of EDT. Could you please tell me how did you troubleshoot and gave a try of PST8PDT, where I failed to do so.

Much needed help from you thanks my friend 🙂

0 Karma

Hemnaath
Motivator

Hi Nickhillscpl, could please guide me on this .

thanks in advance.

0 Karma

nickhills
Ultra Champion

Where is the firewall? - in the world?

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...