Getting Data In

TimeZone setting not working for host set from host_regex?

woodcock
Esteemed Legend

This configuration is not working:

From inputs.conf

[monitor:///somepath/.csv]
host_regex = .
([^])[^].csv(?:.gz)?$
sourcetype = somesourcetype

From props.conf:

[host::PR*]
TZ = US/Atlantic

The host is correctly being set but the TZ is not. Based on this (version 6.1, BTW), I am assuming that if the host value is set using "host_regex", then "host" cannot be used to start a stanza in props.conf, right? If not, why does this not work?

0 Karma
1 Solution

woodcock
Esteemed Legend

OK, I figured it out.

This DOES NOT WORK:

[host::CH...|DA...|NV...]
TZ = US/Central

This DOES WORK:

[host::(CH...|DA...|NV...)]
TZ = US/Central

View solution in original post

0 Karma

woodcock
Esteemed Legend

OK, I figured it out.

This DOES NOT WORK:

[host::CH...|DA...|NV...]
TZ = US/Central

This DOES WORK:

[host::(CH...|DA...|NV...)]
TZ = US/Central

0 Karma

woodcock
Esteemed Legend

Fair enough; my bad.
Even if I fix that, it still doesn't work.
I have another stanza like this which also does not work:

[host::IE*]
TZ = US/Pacific

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Setting the TZ off of the host that has been set with host_regex is totally legit.

However... the Atlantic Standard Time Zone is a Not a US time zone... That's Quebec...

Atlantic Standard Time - Quebec - Lower North Shore (Canada) That's -4:00 with no DST

I imagine however based on the host example you are using that you're looking for Puerto Rico
America/Puerto_Rico which is also -4:00/-4:00 with no DST

http://en.wikipedia.org/wiki/List_of_tz_database_time_zones

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...