Getting Data In

Timezones Timestamps on data

rachelneal
Path Finder

We changed the TZ field from Asia/Shanghai to UTC.

The data that was indexed prior to the change has the "bad" splunk dates on it. Do we need to re-index or something? How can we reset those timestamps?

Tags (1)
0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You can't change already indexed data in Splunk. You could mask the events with | delete to prevent them from showing up in future searches, then re-index the bad data with the TZ settings in place.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...