Getting Data In

Where to set timezone override?

sseekamp
Explorer

We have an environment with a mix of light/heavy forwarders, a deployment server, an indexer, and multiple apps. If I want to set the timezone for a group of servers which props.conf (or other) do I set the TZ = X in? The indexer global, indexer app, deployment server, or forwarder itself?

Tags (2)
0 Karma

lguinn2
Legend

There is a great article on the Splunk wiki: Where do I configure my Splunk settings
The timezone setting goes in props.conf. It MUST be set where the data is parsed, so that means the heavy forwarders AND the indexers. See this answer from S Sorkin; all Sorkin answers are definitive.

MuS
SplunkTrust
SplunkTrust

Hi sseekamp

I would do this on the indexer to keep it simple, but as always there are many ways leading to Rome.

cheers

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...