<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor file on syslog-ng server contains entries for devices with different timezones in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/monitor-file-on-syslog-ng-server-contains-entries-for-devices/m-p/557215#M6235</link>
    <description>&lt;P&gt;I also checked out this link...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps" target="_blank"&gt;Specify time zones for timestamps - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 16:05:31 GMT</pubDate>
    <dc:creator>radam2000</dc:creator>
    <dc:date>2021-06-25T16:05:31Z</dc:date>
    <item>
      <title>monitor file on syslog-ng server contains entries for devices with different timezones</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/monitor-file-on-syslog-ng-server-contains-entries-for-devices/m-p/557091#M6228</link>
      <description>&lt;P&gt;I have a redhat 7.4 syslog-ng server with splunk heavy forwarder(8.1.2)&amp;nbsp; installed. server is TZ EST&lt;/P&gt;&lt;P&gt;Server collects udp/514 logs from multiple networking devices and writes them to textfiles like ...&lt;BR /&gt;/syslogs/todays-internetfirewalls.txt&lt;BR /&gt;/syslogs/todays-routers.txt&lt;BR /&gt;/syslogs/todays-switches.txt&lt;/P&gt;&lt;P&gt;splunk Heavy Forwarder has data/file monitor inputs for the various text files and are assigned to the appropriate index with the appropriate sourcetype&lt;BR /&gt;&lt;BR /&gt;so some network devices sending udp/514 syslogs to the above server are in different timezones but the entries in the text file written do not adjust for timezones...&lt;/P&gt;&lt;P&gt;example screen attached - In screenshot IP 172.24.63.88 is GMT and 172.24.3.5 is EST&lt;BR /&gt;&lt;BR /&gt;I researched and tried to create an app called Timezones on the HF with a local/props.conf file that just lists...&lt;BR /&gt;&lt;BR /&gt;[host::172.24.63.88]&lt;BR /&gt;TZ = GMT&lt;/P&gt;&lt;P&gt;but when file data is ingested the _time for the IP in GMT is same as it appears in the log file entry with no adjustment to bring GMT time to EST time??&lt;BR /&gt;&lt;BR /&gt;any help would be appreciated - I have read several links already and follow a few answers...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Timezones-search-worldwide/td-p/91339" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Timezones-search-worldwide/td-p/91339&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Multiple-time-zones-in-props-conf/m-p/286456#M54667" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Multiple-time-zones-in-props-conf/m-p/286456#M54667&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 23:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/monitor-file-on-syslog-ng-server-contains-entries-for-devices/m-p/557091#M6228</guid>
      <dc:creator>radam2000</dc:creator>
      <dc:date>2021-06-24T23:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: monitor file on syslog-ng server contains entries for devices with different timezones</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/monitor-file-on-syslog-ng-server-contains-entries-for-devices/m-p/557215#M6235</link>
      <description>&lt;P&gt;I also checked out this link...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps" target="_blank"&gt;Specify time zones for timestamps - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 16:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/monitor-file-on-syslog-ng-server-contains-entries-for-devices/m-p/557215#M6235</guid>
      <dc:creator>radam2000</dc:creator>
      <dc:date>2021-06-25T16:05:31Z</dc:date>
    </item>
  </channel>
</rss>

