Splunk ITSI

How to manage _time field with schedule change in Europe zone ?

mah
Builder

Hi, 

With the time change, my logs are shifted by one hour (logs from an HEC input) : 

mah_0-1603790847736.png

It is the same case on many logs from several sources.

Like logs from Azure add-on (the props is correctly set with a TIME_PREFIX on the field Horodate) 

mah_1-1603791260721.png

And same case from other add-on...

How can I fix this ? 

Thank you!

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is the TIME_FORMAT setting in props.conf?

Is the system clock correct?  What time zone does the system use?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mah
Builder

Actually, I have this issue on many logs.

What is the TIME_FORMAT setting in props.conf?

Example of props.conf for the two pictures below :

[sourcetype_picture1]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TRUNCATE = 999999
TIME_PREFIX = \"\@timestamp\"\:
 
[sourcetype_picture2]
SHOULD_LINEMERGE = 0
category = Splunk App Add-on Builder
pulldown_type = 1
INDEXED_EXTRACTIONS = json
TIME_PREFIX = Horodate
 
This both example worked good until the schedule change on Sunday. 
 
Is the system clock correct? 
Actually I did not find a TZ by default for the system. 
This TZ parameter is set on some apps like add-on splunk but sometime it is UTC and sometime it is GMT .
 
What time zone does the system use?
I did not find a TZ by default for the system. 
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...