Getting Data In

TZ Issues When Searching

wbkendall
Explorer

Hello,

We're currently doing a pilot of Splunk. We have two servers - one is an indexer and the other a search head. We have a Linux syslog server that collects all firewall logs and forwards these to the indexer via the Universal Forwarder agent.

All firewalls are set to UTC. This causes an issue when searching for events, as we're in US Eastern time. The only way to get the relevant events to show up in searches is to effectively search in the future relative to our local time (ie compute UTC for the time desired, and search on those values).

I've checked and both the server and the dashboard are set to the correct time zone.

Is there a way to display the time locally in the dashboard while leaving it unmodified within the index?

Thanks!

Tags (1)
0 Karma

wbkendall
Explorer

Thanks everyone. I finally just ended up modifying the props.conf in /opt/splunkforwarder/etc/apps/Splunk_TA-cisco-asa/local/ with this value:

[host:::*]
TZ = US/Eastern

Thanks!

lukejadamec
Super Champion

Check out this information on how Splunk determines the TZ.

http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/ApplyTimezoneOffsetstotimestamps

0 Karma

somesoni2
Revered Legend

You may try setting the timezone of the users to UTC, so that when they search, time range will correspond to UTC.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...