Reporting

Updating the system time on my indexers - how will this affect my indexes/searches etc?

mctester
Communicator

We would like to change all of our system times on our 9 indexers to UTC to help standardize the log times between our security tools.

Will this affect the logs and saved alerts that we have set up. Will we have to modify the time the saved searches run to reflect the new UTC times?

0 Karma
1 Solution

Mick
Splunk Employee
Splunk Employee

Changing the system time on your servers shouldn't affect your scheduled searches or your data in any way. As long as you are extracting the timestamp from the events, and indexing them according to that time, Splunk should continue to work as normal and use those timestamps in the index.

Likewise, assuming that your are one of the standard scheduling methods for your scheduled searches - every hour, every 4 hours, etc - or a simple cron schedule, then they should also continue to work as normal.

The only concerns I would have, is if you have any timezone offsets applied to your data, or if you were using the current system time as your event timestamp - then you may see some adverse effects after you make your update. In fact, you may have to apply some timezone offsets to your data so that the events and timelines are displayed correctly in the UI

View solution in original post

Mick
Splunk Employee
Splunk Employee

Changing the system time on your servers shouldn't affect your scheduled searches or your data in any way. As long as you are extracting the timestamp from the events, and indexing them according to that time, Splunk should continue to work as normal and use those timestamps in the index.

Likewise, assuming that your are one of the standard scheduling methods for your scheduled searches - every hour, every 4 hours, etc - or a simple cron schedule, then they should also continue to work as normal.

The only concerns I would have, is if you have any timezone offsets applied to your data, or if you were using the current system time as your event timestamp - then you may see some adverse effects after you make your update. In fact, you may have to apply some timezone offsets to your data so that the events and timelines are displayed correctly in the UI

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...