I recently updated the SH and indexer to 6.6.2.
My server is in Japan time and the time zone of the splunk administrator user is also Japan time.
And last week I had the opportunity to restart the server.
Then the date of internal log only for about a minute after reboot was the future one day ahead.
I investigated, then the following phenomenon were caught in the search.
”when the hardware clock and the system clock are misaligned, there is a situation that the time shifts in linux.”
Does this phenomenon cause time lag in this internal log?
Also is such a phenomenon a known problem and Is there a workaround?
Could anyone tell me?
↧