Reporting

Updating the system time on my indexers - how will this affect my indexes/searches etc?

mctester
Communicator

We would like to change all of our system times on our 9 indexers to UTC to help standardize the log times between our security tools.

Will this affect the logs and saved alerts that we have set up. Will we have to modify the time the saved searches run to reflect the new UTC times?

0 Karma
1 Solution

Mick
Splunk Employee
Splunk Employee

Changing the system time on your servers shouldn't affect your scheduled searches or your data in any way. As long as you are extracting the timestamp from the events, and indexing them according to that time, Splunk should continue to work as normal and use those timestamps in the index.

Likewise, assuming that your are one of the standard scheduling methods for your scheduled searches - every hour, every 4 hours, etc - or a simple cron schedule, then they should also continue to work as normal.

The only concerns I would have, is if you have any timezone offsets applied to your data, or if you were using the current system time as your event timestamp - then you may see some adverse effects after you make your update. In fact, you may have to apply some timezone offsets to your data so that the events and timelines are displayed correctly in the UI

View solution in original post

Mick
Splunk Employee
Splunk Employee

Changing the system time on your servers shouldn't affect your scheduled searches or your data in any way. As long as you are extracting the timestamp from the events, and indexing them according to that time, Splunk should continue to work as normal and use those timestamps in the index.

Likewise, assuming that your are one of the standard scheduling methods for your scheduled searches - every hour, every 4 hours, etc - or a simple cron schedule, then they should also continue to work as normal.

The only concerns I would have, is if you have any timezone offsets applied to your data, or if you were using the current system time as your event timestamp - then you may see some adverse effects after you make your update. In fact, you may have to apply some timezone offsets to your data so that the events and timelines are displayed correctly in the UI

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...