Getting Data In

Is there a way to change the Timezone (TZ) of OLD already indexed data

bishtk
Communicator

Dear Splunk Professionals,

We have a requirement here to change/correct the TZ settings as few sourcetype are having different TZ and others have different. We have configured TZ wrt [my_sourcetype] in indexer's props.conf.
Bu doing this the new event is coming with proper Timestamp TZ now. But the old already indexed data is with old Timezone only.
So wanted to check if any of you have any solution for this?

Thanks,

0 Karma

deepashri_123
Motivator

Hey kundanbisht,

You cannot make any changes in TZ once the data is indexed.
However you can clean and re-index the data adding crc_salt.
This will add TZ in your data which is indexed again.

Let me know if this helps!!

0 Karma

bishtk
Communicator

hi deepashri,

Thank you. I already figured that re-indexing is only option but just thought to raise it over forums to check if there exists any alternate solution.

https://answers.splunk.com/answers/52755/timezones-timestamps-on-data.html?utm_source=typeahead&utm_...

0 Karma

bishtk
Communicator

@deepashri_123 : A query related to re-indexing - We are using Splunk SaaS big setup here as per client's Application need. The logs from application servers are getting mounted via filers (autofs) to a separate server where UF is installed. From those mounted filers the UF fetch and forward the data to Splunk Cloud Indexer.
Now the twist here is that, all the data (logs, zip, etc) inside those filers mount are rolling data. By that i mean , it gets deleted after certain period of time and replaced with new files.
In this case, could you please suggest how any kind of re-indexing option would work? (be it cleaning fishbucket/crcSalt/initCrcLength/btprobe).

0 Karma

deepashri_123
Motivator

Since the data is not available can you try following options
1. Export raw data for the time period the TZ was wrong and reindex again.
2. Also you can try converting TZ in search time(Needs to be tested)

You can refer the link below:
https://answers.splunk.com/answers/224134/force-displayed-timezone-in-results-to-be-utc-not-1.html#a...
https://answers.splunk.com/answers/241917/timezone-conversion-function.html

0 Karma

bishtk
Communicator

@deepashri_123 Thanks. But I don't think that's going to be convenient, as said we are using Splunk Cloud environment here and have no access to Splunk Cloud part i.e. Indexer, Searchhead etc.
Only access we have is of Universal Forwarders.
Also its a big environment and to ask for rawdata, will have to raise support case to Splunk Cloud people. Not sure how they will react to it.

0 Karma

deepashri_123
Motivator

To convert timezone at search time you don't need access to search head cli, you need to convert it in search time.

Refer this link:
https://answers.splunk.com/answers/241917/timezone-conversion-function.html
https://answers.splunk.com/answers/135380/eval-to-find-current-time-in-another-timezone.html

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...