Splunk Enterprise

Need help synchronizing Hosts( Linux, Windows) servers with Splunk Ent. & ES. I appreciate any directions on how to plan

SamHTexas
Builder

I have a large environment that the TZs between hosts & Splunk are off by minutes & hours at times. How do I get started ? If you have done such a project please share the procedures - any helpful SPLs. Thanks a million.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As I already told you - it's out of the scope of splunk administration itself. In a properly maintained infrastructure  you use a common time source (usually a NTP sever(s)) to which other components sync.

Then it's up to event source systems to either configure logging with common timezone (preferably GMT) and/or make the source include the TZ info in timestamps.

If it's not possible it's up to the splunk admin to configure apropriate TZ offset on for particular inputs/sources/sourcetypes.

Nothing automatic here.

As I already wrote you, you can check the difference between the time reported in the event and the time it was indexed but that's it.

0 Karma

Stefanie
Builder

My suggestion would be to manually edit the props.conf for your hosts to set the TZ.

Please see check this link for an example and TZ attributes: https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Applytimezoneoffsetstotimestamps 

Another option would be to set up an NTP server and point all hosts and Splunk servers to that server.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...