Splunk Search

What will happen on indexed data if we revert system time?

crt89
Communicator

Hi,

We have a set of indexed logs from a server currently there's no new data that has been indexed. The data computes the count of certain values (ex Total Percentage of Rejected SMS count vs Succeessfull SMS count). We are currently checking the results of Splunk to our manual computation. We have found out that we have a high variance but the percentage count is not that high. Upon checking we found out that the server time is 9 hours advance on our time.

My question is what will happen if we tried to change the server time? Will the data be re-indexed? We are not sure if this was the problem with the count of our variance.

Thanks,

crt

0 Karma
1 Solution

dshpritz
SplunkTrust
SplunkTrust

Splunk stores the event time in epoch. This is an integer, which represents the number of seconds since 1/1/1970. Setting the system time back will not change the stored event time, nor will Splunk re-index the data.

View solution in original post

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Splunk stores the event time in epoch. This is an integer, which represents the number of seconds since 1/1/1970. Setting the system time back will not change the stored event time, nor will Splunk re-index the data.

0 Karma

yannK
Splunk Employee
Splunk Employee

Beware, the indexed events that will now be in the future will not returned by a search.
Until they are no more in the future 🙂

0 Karma

crt89
Communicator

Thanks for your reply, so its safe to revert our server time back. We'll try again to search hope to be able to have a much lower variance.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...