Getting Data In

universal forwarder - set timezone

jhallman
Explorer

Forwarder is in US/Pacific and splunk indexer is in EST. Where do I need to set the timezone so _time has the correct time when I search for events.

Example..logfile tmp/SQL_IO_Write_stats.sigsfpip1.run.log looks likes this (right now it runs 10min after the hour) and logs the IO for each DB into this file.

Aug 23 2011 04:10PM 5 HALO 113326168 103536 14318436352 66323611648 00000000000007a8 1

Aug 23 2011 04:10PM 7 Matrics 78072770 54788 7857946624 41943040000 00000000000007a0

[default]
host = myhost
[monitor:///tmp/SQL_IO_Write_stats.sigsfpip1.run.log]
crcSalt =
disabled = false
followTail = 0
index = db_stats
sourcetype = db_stats

on searches host="myhost"
_time shows

8/23/11 4:00:00.000 AM

Tags (1)
0 Karma

lguinn2
Legend

For timezone, you do not have a choice; for some other settings, you do. You must set the timezone where the parsing occurs. See this definitive answer from S Sorkin. I second rroberts recommendation of the Where do I configure my Splunk settings?

rroberts
Splunk Employee
Splunk Employee

reynard082
New Member

I also have that same question, is it better to do the TZ on the universal forwarder, the indexer, or the search head?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...