When I do a search on my search head for all time, I see correct time stamps in standard EST. When I do a 15 minute search, I see time stamps from 5 hours ago.
My search head and indexer are both set to CST on the OS, and the logs are coming in in EST which has been defined in props.conf.
Does anyone know why this could be happening?
This is an image of my sourcetype time stamps, vs my system clock (CST).
In lukejadamec's comments, he mentioned that splunk thought my system time was off. I set the time zone and time settings manually during OS installation, but never checked them after that. When i did, they reflected GMT time.
I adjusted these settings to EST, and all timestamps are current now, and the issue has been resolved.
In lukejadamec's comments, he mentioned that splunk thought my system time was off. I set the time zone and time settings manually during OS installation, but never checked them after that. When i did, they reflected GMT time.
I adjusted these settings to EST, and all timestamps are current now, and the issue has been resolved.
Yea. This was starting to give me heartburn 🙂
negative... but when I looked at my OS on both the indexer and the SH it was in GMT. I set it to CST during install, and didnt' check it after that. I am reconfiguring it now to be in EST and we will see what happens.
If this is a recent event, then the timestamp is GMT.
Are you configuring the TZ in props.conf on the indexer by host?
Raw print of an event for 15 minute search of a sourcetype:
Query:
sourcetype=
INFO
Splunk thinks your system time is GMT, so since your user timezone is set to EST it is adjusting the displayed time. You can check this by setting your user timezone to GMT.
I'm also curious about the timestamps in the _raw
output
That includes windows Perfmon
This is happening on all sourcetypes. I'm sure there is a global setting somewhere that I am missing, but I couldn't tell you what it is to save my life.
Is this for all data, or just certain sources?
This is also happening on any user that logs into my search head.
It is set to EST
What is your splunk user timezone property set to?