Getting Data In

universal forwarder - set timezone

jhallman
Explorer

Forwarder is in US/Pacific and splunk indexer is in EST. Where do I need to set the timezone so _time has the correct time when I search for events.

Example..logfile tmp/SQL_IO_Write_stats.sigsfpip1.run.log looks likes this (right now it runs 10min after the hour) and logs the IO for each DB into this file.

Aug 23 2011 04:10PM 5 HALO 113326168 103536 14318436352 66323611648 00000000000007a8 1

Aug 23 2011 04:10PM 7 Matrics 78072770 54788 7857946624 41943040000 00000000000007a0

[default]
host = myhost
[monitor:///tmp/SQL_IO_Write_stats.sigsfpip1.run.log]
crcSalt =
disabled = false
followTail = 0
index = db_stats
sourcetype = db_stats

on searches host="myhost"
_time shows

8/23/11 4:00:00.000 AM

Tags (1)
0 Karma

lguinn2
Legend

For timezone, you do not have a choice; for some other settings, you do. You must set the timezone where the parsing occurs. See this definitive answer from S Sorkin. I second rroberts recommendation of the Where do I configure my Splunk settings?

rroberts
Splunk Employee
Splunk Employee

reynard082
New Member

I also have that same question, is it better to do the TZ on the universal forwarder, the indexer, or the search head?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...