Getting Data In

Timezones Timestamps on data

rachelneal
Path Finder

We changed the TZ field from Asia/Shanghai to UTC.

The data that was indexed prior to the change has the "bad" splunk dates on it. Do we need to re-index or something? How can we reset those timestamps?

Tags (1)
0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You can't change already indexed data in Splunk. You could mask the events with | delete to prevent them from showing up in future searches, then re-index the bad data with the TZ settings in place.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...