Getting Data In

TimeZone setting not working for host set from host_regex?

woodcock
Esteemed Legend

This configuration is not working:

From inputs.conf

[monitor:///somepath/.csv]
host_regex = .
([^])[^].csv(?:.gz)?$
sourcetype = somesourcetype

From props.conf:

[host::PR*]
TZ = US/Atlantic

The host is correctly being set but the TZ is not. Based on this (version 6.1, BTW), I am assuming that if the host value is set using "host_regex", then "host" cannot be used to start a stanza in props.conf, right? If not, why does this not work?

0 Karma
1 Solution

woodcock
Esteemed Legend

OK, I figured it out.

This DOES NOT WORK:

[host::CH...|DA...|NV...]
TZ = US/Central

This DOES WORK:

[host::(CH...|DA...|NV...)]
TZ = US/Central

View solution in original post

0 Karma

woodcock
Esteemed Legend

OK, I figured it out.

This DOES NOT WORK:

[host::CH...|DA...|NV...]
TZ = US/Central

This DOES WORK:

[host::(CH...|DA...|NV...)]
TZ = US/Central

0 Karma

woodcock
Esteemed Legend

Fair enough; my bad.
Even if I fix that, it still doesn't work.
I have another stanza like this which also does not work:

[host::IE*]
TZ = US/Pacific

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Setting the TZ off of the host that has been set with host_regex is totally legit.

However... the Atlantic Standard Time Zone is a Not a US time zone... That's Quebec...

Atlantic Standard Time - Quebec - Lower North Shore (Canada) That's -4:00 with no DST

I imagine however based on the host example you are using that you're looking for Puerto Rico
America/Puerto_Rico which is also -4:00/-4:00 with no DST

http://en.wikipedia.org/wiki/List_of_tz_database_time_zones

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...