Splunk Enterprise

Need help synchronizing Hosts( Linux, Windows) servers with Splunk Ent. & ES. I appreciate any directions on how to plan

SamHTexas
Builder

I have a large environment that the TZs between hosts & Splunk are off by minutes & hours at times. How do I get started ? If you have done such a project please share the procedures - any helpful SPLs. Thanks a million.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As I already told you - it's out of the scope of splunk administration itself. In a properly maintained infrastructure  you use a common time source (usually a NTP sever(s)) to which other components sync.

Then it's up to event source systems to either configure logging with common timezone (preferably GMT) and/or make the source include the TZ info in timestamps.

If it's not possible it's up to the splunk admin to configure apropriate TZ offset on for particular inputs/sources/sourcetypes.

Nothing automatic here.

As I already wrote you, you can check the difference between the time reported in the event and the time it was indexed but that's it.

0 Karma

Stefanie
Builder

My suggestion would be to manually edit the props.conf for your hosts to set the TZ.

Please see check this link for an example and TZ attributes: https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Applytimezoneoffsetstotimestamps 

Another option would be to set up an NTP server and point all hosts and Splunk servers to that server.

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...