Splunk Enterprise

Need help synchronizing Hosts( Linux, Windows) servers with Splunk Ent. & ES. I appreciate any directions on how to plan

SamHTexas
Builder

I have a large environment that the TZs between hosts & Splunk are off by minutes & hours at times. How do I get started ? If you have done such a project please share the procedures - any helpful SPLs. Thanks a million.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As I already told you - it's out of the scope of splunk administration itself. In a properly maintained infrastructure  you use a common time source (usually a NTP sever(s)) to which other components sync.

Then it's up to event source systems to either configure logging with common timezone (preferably GMT) and/or make the source include the TZ info in timestamps.

If it's not possible it's up to the splunk admin to configure apropriate TZ offset on for particular inputs/sources/sourcetypes.

Nothing automatic here.

As I already wrote you, you can check the difference between the time reported in the event and the time it was indexed but that's it.

0 Karma

Stefanie
Builder

My suggestion would be to manually edit the props.conf for your hosts to set the TZ.

Please see check this link for an example and TZ attributes: https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Applytimezoneoffsetstotimestamps 

Another option would be to set up an NTP server and point all hosts and Splunk servers to that server.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...