Hey,
I have an index where each event starts with a UTC timestamp. It is using this UTC timestamp for the _time field. Instead I would like for all events in this index to use the Splunk server timezone for the _time field. How can I configure Splunk to do this?
Thanks.
The answer to this question can be found here:
http://splunk-base.splunk.com/answers/57543/splunk-displaying-events-with-the-correct-timezone
The answer to this question can be found here:
http://splunk-base.splunk.com/answers/57543/splunk-displaying-events-with-the-correct-timezone
the former please. Thanks
You could try to assign the timezone in your props.conf
are you saying you want the timestamp interpreted as if it were in the Splunk indexer timezone instead of in UTC, or do you mean you want to display the (UTC) timestamp in the Splunk server timezone?