How do I change the timezone offset for events that appear to be from the same host (but the real host and timezone is contained in the event)?
RAW EVENTS:
Event 1:
host=HOSTA
real_event_host=HOSTX
real_event_time=2018-09-25T06:39:03:142-06:00
Event 2:
host=HOSTA
real_event_host=HOSTY
real_event_time=2018-09-25T08:40:03:142-04:00
Here is how the above events get loaded:
Event 1:
_time=25/09/2018 06:39:03.000 (What I want is for this to now switch to the timezone of the indexer -400 i.e. 25/09/2018 08:39:03.142)
host=HOSTA
real_event_host=HOSTX
real_event_time=2018-09-25T06:39:03:142-06:00
Event 2:
_time=25/09/2018 08:40:03.321 (For this one the timezone is the same so the times should be the same)
host=HOSTA
real_event_host=HOSTY
real_event_time=2018-09-25T08:40:03:321-04:00
**How do I either use the real_event_time as the _time and convert it to the indexer's timezone OR at the very least make the _time reflect the timezone of the event?
HOSTX is in -600 timezone offset
HOSTY is in -400 timezone offset
Both events appear to come from HOSTA which is in -400 timezone offset because HOSTA is a log aggregator**