Splunk Enterprise

Need help synchronizing Hosts( Linux, Windows) servers with Splunk Ent. & ES. I appreciate any directions on how to plan

SamHTexas
Builder

I have a large environment that the TZs between hosts & Splunk are off by minutes & hours at times. How do I get started ? If you have done such a project please share the procedures - any helpful SPLs. Thanks a million.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As I already told you - it's out of the scope of splunk administration itself. In a properly maintained infrastructure  you use a common time source (usually a NTP sever(s)) to which other components sync.

Then it's up to event source systems to either configure logging with common timezone (preferably GMT) and/or make the source include the TZ info in timestamps.

If it's not possible it's up to the splunk admin to configure apropriate TZ offset on for particular inputs/sources/sourcetypes.

Nothing automatic here.

As I already wrote you, you can check the difference between the time reported in the event and the time it was indexed but that's it.

0 Karma

Stefanie
Builder

My suggestion would be to manually edit the props.conf for your hosts to set the TZ.

Please see check this link for an example and TZ attributes: https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Applytimezoneoffsetstotimestamps 

Another option would be to set up an NTP server and point all hosts and Splunk servers to that server.

 

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...