<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time Conversion of Cisco FTD Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-Conversion-of-Cisco-FTD-Logs/m-p/567547#M100797</link>
    <description>&lt;P&gt;Splunk will convert the time zone for you.&amp;nbsp; You just need to tell it what time zone the event occurs in.&amp;nbsp; Do that by specifying &lt;FONT face="courier new,courier"&gt;TZ = UTC&lt;/FONT&gt; in props.conf for the appropriate sourcetype.&lt;/P&gt;&lt;P&gt;I'd be remiss if I missed this opportunity to point out that one should not send syslog directly to a Splunk TCP or UDP port.&amp;nbsp; Instead, send it to a dedicated syslog server and forward it to Splunk or use Splunk Connect for Syslog.&lt;/P&gt;</description>
    <pubDate>Sun, 19 Sep 2021 14:25:11 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-09-19T14:25:11Z</dc:date>
    <item>
      <title>Time Conversion of Cisco FTD Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Conversion-of-Cisco-FTD-Logs/m-p/567544#M100796</link>
      <description>&lt;P&gt;I have several Cisco FTD devices (managed by Cisco FMC) that are sending syslog messages to splunk. Here is the format....&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;164&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Sep&lt;/SPAN&gt; &lt;SPAN class="t"&gt;19&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;13:26:27&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ftdv-b-int&lt;/SPAN&gt; &lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;%FTD-4-313005:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;No&lt;/SPAN&gt; &lt;SPAN class="t"&gt;matching&lt;/SPAN&gt; &lt;SPAN class="t"&gt;connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;for&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ICMP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;error&lt;/SPAN&gt; &lt;SPAN class="t"&gt;message:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;icmp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;src&lt;/SPAN&gt; &lt;SPAN class="t"&gt;inside_Mgmt:10.0.20.238&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dst&lt;/SPAN&gt; &lt;SPAN class="t"&gt;inside_Legacy_Server:192.168.0.94&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;type&lt;/SPAN&gt; &lt;SPAN class="t"&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;code&lt;/SPAN&gt; &lt;SPAN class="t"&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;on&lt;/SPAN&gt; &lt;SPAN class="t"&gt;inside_Mgmt&lt;/SPAN&gt; &lt;SPAN class="t"&gt;interface.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Original&lt;/SPAN&gt; &lt;SPAN class="t"&gt;IP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;payload:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;udp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;src&lt;/SPAN&gt; &lt;SPAN class="t"&gt;192.168.0.94/53&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dst&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.0.20.238/12055.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The time is in UTC.... is there a way to convert this time to local when I pull the records in so I can do alerting, etc. on these records?&lt;/P&gt;</description>
      <pubDate>Sun, 19 Sep 2021 13:38:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Conversion-of-Cisco-FTD-Logs/m-p/567544#M100796</guid>
      <dc:creator>teco_akelly</dc:creator>
      <dc:date>2021-09-19T13:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Time Conversion of Cisco FTD Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-Conversion-of-Cisco-FTD-Logs/m-p/567547#M100797</link>
      <description>&lt;P&gt;Splunk will convert the time zone for you.&amp;nbsp; You just need to tell it what time zone the event occurs in.&amp;nbsp; Do that by specifying &lt;FONT face="courier new,courier"&gt;TZ = UTC&lt;/FONT&gt; in props.conf for the appropriate sourcetype.&lt;/P&gt;&lt;P&gt;I'd be remiss if I missed this opportunity to point out that one should not send syslog directly to a Splunk TCP or UDP port.&amp;nbsp; Instead, send it to a dedicated syslog server and forward it to Splunk or use Splunk Connect for Syslog.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Sep 2021 14:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-Conversion-of-Cisco-FTD-Logs/m-p/567547#M100797</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-19T14:25:11Z</dc:date>
    </item>
  </channel>
</rss>

