Getting Data In

Why is event time different from server time?

Sept11
Loves-to-Learn Lots

Hi all,

we have migrated HF where DB connect app was installed and now events from DB app on new HF have different timestamp. 1 hour is missing from server time.

They are using same indexers. There is not TZ configured in props.conf on indexers.

Those configurations in DB app do not work:
1. Configuration -> Databases -> Connections -> "your connection" (Timezone dropdown)

2. Add the following to the JVM options in the configuration tab of the DB connect app:
-Duser.timezone=GMT

 

New HF:

 

1. The time should be 3:30 as server/hf has EDT time 3:30 (This works correctly on old HF, there is time t-6, not t-7). If this is not time from server/when was event created what is it then? I am confused here.
9:30 is ok, as we are CET.

 new_event_time.PNG

 

2.new_time.PNG

3. The server time of new HF is correct. So why events miss 1 hour? 

 new_server_time.PNG


Old HF:

1.old_event_time.PNG


2.old_time.PNG

3.timedatectl (I took ss 9 mins later)
timedatectl.PNG

Thank you for every idea.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...