Hello there,
I would like to convert the default time to the local country timezone and place the converted timezone next to the default one
The defaut timezone is Central European time and based on the country name available in the report, need to conver the timezone. I guess i need to have a lookup table which the coutryname and the timezone of that country
Timestamp | CountryCode | CountryName | Region |
2023-10-29T13:15:51.711Z | BR | Brazil | Americas |
2023-10-30T10:13:19.160Z | BH | Bahrain | APEC |
2023-10-30T19:15:24.263Z | AE | Arab Emirates | APEC |
Splunk doesn't really offer a means to convert time zones since each user has the ability to set their own preferred time zone.
If you really want to do it, then your lookup table will need to provide the offset from the default time zone to the local country time zone. The you should be able to pass that value to the relative_time function.
Splunk doesn't really offer a means to convert time zones since each user has the ability to set their own preferred time zone.
If you really want to do it, then your lookup table will need to provide the offset from the default time zone to the local country time zone. The you should be able to pass that value to the relative_time function.
Worked, thanks