Getting Data In

Why is event time different from server time?

Sept11
Loves-to-Learn Lots

Hi all,

we have migrated HF where DB connect app was installed and now events from DB app on new HF have different timestamp. 1 hour is missing from server time.

They are using same indexers. There is not TZ configured in props.conf on indexers.

Those configurations in DB app do not work:
1. Configuration -> Databases -> Connections -> "your connection" (Timezone dropdown)

2. Add the following to the JVM options in the configuration tab of the DB connect app:
-Duser.timezone=GMT

 

New HF:

 

1. The time should be 3:30 as server/hf has EDT time 3:30 (This works correctly on old HF, there is time t-6, not t-7). If this is not time from server/when was event created what is it then? I am confused here.
9:30 is ok, as we are CET.

 new_event_time.PNG

 

2.new_time.PNG

3. The server time of new HF is correct. So why events miss 1 hour? 

 new_server_time.PNG


Old HF:

1.old_event_time.PNG


2.old_time.PNG

3.timedatectl (I took ss 9 mins later)
timedatectl.PNG

Thank you for every idea.

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...