Getting Data In

Reconcile hosts from multiple timezones in splunk?

msarro
Builder

Hey everyone.
I'm wondering how this is possible to accomplish - we have windows server farms across numerous timezones. They all send data to the same group of indexers, which convert everything to UTC.

If all of the windows servers are configured to use their local timezones, but the indexers only have a single props.conf file overriding time zones, how can we specify different time zones for the different servers?

Is it possible to override at the outputs.conf level on the forwarder itself, so I can effectively send out a small app to all of my forwarders that specifies "all hosts, send your data as if it was UTC"?

Everything specifies that this has to be overridden at the input level, but only a single timezone can be specified for a particular input. If you have servers from two timezones sending the same type of input, there needs to be an additional way to specify.

Obviously the best way to do this would to have all of the windows farms running UTC, but it's not my environment, so I can't really dictate that to another team.

Tags (1)

conor_splunk
Path Finder

I have the same question, did you ever get anywhere with this?

http://answers.splunk.com/answers/130913/splunk-and-different-timezones

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...