Getting Data In

Timestamp setting

Ant1D
Motivator

Hey,

I have an index where each event starts with a UTC timestamp. It is using this UTC timestamp for the _time field. Instead I would like for all events in this index to use the Splunk server timezone for the _time field. How can I configure Splunk to do this?

Thanks.

0 Karma
1 Solution

Ant1D
Motivator
0 Karma

Ant1D
Motivator
0 Karma

Ant1D
Motivator

the former please. Thanks

0 Karma

allamiro
Path Finder

You could try to assign the timezone in your props.conf

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

are you saying you want the timestamp interpreted as if it were in the Splunk indexer timezone instead of in UTC, or do you mean you want to display the (UTC) timestamp in the Splunk server timezone?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...