Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk Exam SPLK-1003 Topic 1 Question 99 Discussion

Actual exam question for Splunk's SPLK-1003 exam
Question #: 99
Topic #: 1
[All SPLK-1003 Questions]

A Universal Forwarder has the following active stanza in inputs . conf:

[monitor: //var/log]

disabled = O

host = 460352847

An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?

Show Suggested Answer Hide Answer
Suggested Answer: D

The correct answer is D. The timezone of the forwarder will be added to the event as part of indexing.

According to the Splunk documentation1, Splunk software determines the time zone to assign to a timestamp using the following logic in order of precedence:

Use the time zone specified in raw event data (for example, PST, -0800), if present.

Use the TZ attribute set in props.conf, if the event matches the host, source, or source type that the stanza specifies.

If the forwarder and the receiving indexer are version 6.0 or higher, use the time zone that the forwarder provides.

Use the time zone of the host that indexes the event.

In this case, the event does not have a time zone specified in the raw data, nor does it have a TZ attribute set in props.conf. Therefore, the next rule applies, which is to use the time zone that the forwarder provides. A universal forwarder is a lightweight agent that can forward data to a Splunk deployment, and it knows its system time zone and sends that information along with the events to the indexer2. The indexer then converts the event time to UTC and stores it in the _time field1.

The other options are incorrect because:

A) Universal Coordinated Time (UTC) is not the time zone that Splunk adds to the event as part of indexing, but rather the time zone that Splunk uses to store the event time in the _time field. Splunk software converts the event time to UTC based on the time zone that it determines from the rules above1.

B) The timezone of the search head is not relevant for indexing, as the search head is a Splunk component that handles search requests and distributes them to indexers, but it does not process incoming data3. The search head uses the user's timezone setting to determine the time range in UTC that should be searched and to display the timestamp of the results in the user's timezone2.

C) The timezone of the indexer that indexed the event is only used as a last resort, if none of the other rules apply. In this case, the forwarder provides the time zone information, so the indexer does not use its own time zone1.


Contribute your Thoughts:

Aileen
13 days ago
I'm not sure, but I think it's C) The timezone of the indexer that indexed the event.
upvoted 0 times
...
Rene
13 days ago
A) Universal Coordinated Time. Because who needs timezones, am I right? Just give me the time in UTC and I'll figure it out.
upvoted 0 times
...
Gerald
14 days ago
I agree with Aleta. The forwarder adds its timezone to the event.
upvoted 0 times
...
Izetta
17 days ago
I'm going with B) The timezone of the search head. That's where the data is being queried, so that's the timezone that should be applied.
upvoted 0 times
...
Nieves
20 days ago
C) The timezone of the indexer that indexed the event. The indexer is the one actually processing the event, so it should determine the timezone.
upvoted 0 times
Verdell
3 days ago
B) The timezone of the search head.
upvoted 0 times
...
Bulah
8 days ago
A) Universal Coordinated Time.
upvoted 0 times
...
...
Aleta
22 days ago
I think the answer is D) The timezone of the forwarder.
upvoted 0 times
...
Jeanice
22 days ago
D) The timezone of the forwarder. Makes sense to me, since the forwarder is the one collecting the log data.
upvoted 0 times
Toi
8 days ago
C) The timezone of the indexer that indexed the event.
upvoted 0 times
...
Whitley
10 days ago
B) The timezone of the search head.
upvoted 0 times
...
Earleen
15 days ago
A) Universal Coordinated Time.
upvoted 0 times
...
...

Save Cancel