|
I am trying to make sure my timezones for devices logging to splunk are correct. I have noticed as part of the date extractions that there is a field called date_zone. the values for all my devices are 'local'. what is this field extracting and should it reference GMT or UTC if that timezone indicator is in the timestamp on the syslog message? |
|
This Splunk-internal index-time field will take one of two values :
|