Getting Data In

Why is event time different from server time?

Sept11
Loves-to-Learn Lots

Hi all,

we have migrated HF where DB connect app was installed and now events from DB app on new HF have different timestamp. 1 hour is missing from server time.

They are using same indexers. There is not TZ configured in props.conf on indexers.

Those configurations in DB app do not work:
1. Configuration -> Databases -> Connections -> "your connection" (Timezone dropdown)

2. Add the following to the JVM options in the configuration tab of the DB connect app:
-Duser.timezone=GMT

 

New HF:

 

1. The time should be 3:30 as server/hf has EDT time 3:30 (This works correctly on old HF, there is time t-6, not t-7). If this is not time from server/when was event created what is it then? I am confused here.
9:30 is ok, as we are CET.

 new_event_time.PNG

 

2.new_time.PNG

3. The server time of new HF is correct. So why events miss 1 hour? 

 new_server_time.PNG


Old HF:

1.old_event_time.PNG


2.old_time.PNG

3.timedatectl (I took ss 9 mins later)
timedatectl.PNG

Thank you for every idea.

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...