Getting Data In

Splunk displaying events with the correct timezone

Ant1D
Motivator

Hi,

I have some data in an index where the events all begin with a UTC timestamp. My Splunk indexer server is in the UK and I would like the timestamps for these events to be interpreted as being in the Splunk indexer timezone (UK) instead of the UTC.

How can I do this?

At present, if a new event arrives at 11AM UK time, the timestamp will say 10AM which is the UTC time so it means that any searches that I do over the last 60 minutes or less will return no results which should not be the case.

Thanks in advance for your help.

1 Solution

Ant1D
Motivator

The solution is to make the following addition to your props.conf file:

[the_sourcetype_name]
TZ = the_timezone_that_your_timestamps_are_in

For this question, you would need to add TZ = UTC

View solution in original post

0 Karma

Ant1D
Motivator

The solution is to make the following addition to your props.conf file:

[the_sourcetype_name]
TZ = the_timezone_that_your_timestamps_are_in

For this question, you would need to add TZ = UTC

0 Karma

whitewool
Splunk Employee
Splunk Employee
0 Karma

Ant1D
Motivator

thanks for the link

0 Karma

Ant1D
Motivator

I tried using the TZ = value attribute before and it didn't work. I guess I can try this again

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi Ant1D

have you check the docs on how to set different timezones?

cheers,

MuS

0 Karma

Ant1D
Motivator

thanks for the link

0 Karma

Ant1D
Motivator

Looks to be working now

0 Karma

Ant1D
Motivator

I tried using the TZ = value attribute before and it didn't work. I guess I can try this again

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...