Thank you for you advise, I wonder how can I modify events before indexing in wineventlog. And what make me confused is why splunk forwarder doesn't add timezone info in winevent logs. Although TZ can make `_time` equals to raw time in logs, that is not the real time log reported in my timezone and will add persistent work to remind others that we have some logs not in our timezone and blabla... I need to manage the log uniformly instead of divide it into different indexes by timezone. Thank you.
... View more