Getting Data In

Splunk - Server and Application logs timestamps are different

vilashegde
New Member

We have a set of servers where the server Timezone is in PST/PDT but the application running on that server has log timestamps in UTC. We have setup some Alerts on those servers. Due to the timestamp mis-match, the alerts are triggered with the delay of 7 or 8 hours depending on whether Daylight saving is in effect (Since PST = UTC-8 and PDT=UTC-7). Splunk is considering the application log timestamp in PST/PDT and reporting accordingly.
Is there any way around this? Please suggest.

Tags (1)
0 Karma

renjith_nair
Legend

Hi @vilashegde,

You can set the timezones for events in props conf as mentioned in Apply timezone offsets to timestamps
This could be done based on the source or sourcetype or host

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...