Getting Data In
Highlighted

Is there a way to change the Timezone (TZ) of OLD already indexed data

Path Finder

Dear Splunk Professionals,

We have a requirement here to change/correct the TZ settings as few sourcetype are having different TZ and others have different. We have configured TZ wrt [my_sourcetype] in indexer's props.conf.
Bu doing this the new event is coming with proper Timestamp TZ now. But the old already indexed data is with old Timezone only.
So wanted to check if any of you have any solution for this?

Thanks,

0 Karma
Highlighted

Re: Is there a way to change the Timezone (TZ) of OLD already indexed data

Motivator

Hey kundanbisht,

You cannot make any changes in TZ once the data is indexed.
However you can clean and re-index the data adding crc_salt.
This will add TZ in your data which is indexed again.

Let me know if this helps!!

0 Karma
Highlighted

Re: Is there a way to change the Timezone (TZ) of OLD already indexed data

Path Finder

hi deepashri,

Thank you. I already figured that re-indexing is only option but just thought to raise it over forums to check if there exists any alternate solution.

https://answers.splunk.com/answers/52755/timezones-timestamps-on-data.html?utm_source=typeahead&utm_...

0 Karma
Highlighted

Re: Is there a way to change the Timezone (TZ) of OLD already indexed data

Path Finder

@deepashri_123 : A query related to re-indexing - We are using Splunk SaaS big setup here as per client's Application need. The logs from application servers are getting mounted via filers (autofs) to a separate server where UF is installed. From those mounted filers the UF fetch and forward the data to Splunk Cloud Indexer.
Now the twist here is that, all the data (logs, zip, etc) inside those filers mount are rolling data. By that i mean , it gets deleted after certain period of time and replaced with new files.
In this case, could you please suggest how any kind of re-indexing option would work? (be it cleaning fishbucket/crcSalt/initCrcLength/btprobe).

0 Karma
Highlighted

Re: Is there a way to change the Timezone (TZ) of OLD already indexed data

Motivator

Since the data is not available can you try following options
1. Export raw data for the time period the TZ was wrong and reindex again.
2. Also you can try converting TZ in search time(Needs to be tested)

You can refer the link below:
https://answers.splunk.com/answers/224134/force-displayed-timezone-in-results-to-be-utc-not-1.html#a...
https://answers.splunk.com/answers/241917/timezone-conversion-function.html

0 Karma
Highlighted

Re: Is there a way to change the Timezone (TZ) of OLD already indexed data

Path Finder

@deepashri_123 Thanks. But I don't think that's going to be convenient, as said we are using Splunk Cloud environment here and have no access to Splunk Cloud part i.e. Indexer, Searchhead etc.
Only access we have is of Universal Forwarders.
Also its a big environment and to ask for rawdata, will have to raise support case to Splunk Cloud people. Not sure how they will react to it.

0 Karma
Highlighted

Re: Is there a way to change the Timezone (TZ) of OLD already indexed data

Motivator

To convert timezone at search time you don't need access to search head cli, you need to convert it in search time.

Refer this link:
https://answers.splunk.com/answers/241917/timezone-conversion-function.html
https://answers.splunk.com/answers/135380/eval-to-find-current-time-in-another-timezone.html

0 Karma