<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting wrong time for event in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625392#M107485</link>
    <description>&lt;P&gt;I assume it's caused because of the IST in the event but I don't know how to change it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wrong time.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23155iF979A6A8AE460DA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="wrong time.jpeg" alt="wrong time.jpeg" /&gt;&lt;/span&gt;Can you help?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Dec 2022 08:13:52 GMT</pubDate>
    <dc:creator>olivera</dc:creator>
    <dc:date>2022-12-28T08:13:52Z</dc:date>
    <item>
      <title>Getting wrong time for event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625285#M107466</link>
      <description>&lt;P&gt;I have an add on for unix and linux downloaded on my monitored servers and the data is sent to my indexers.&lt;/P&gt;
&lt;P&gt;In the Unix:Service sourcetype the time that is wrriten is 3.5 hours delayed, meanwhile the time that is wrriten in the event itself is the correct time.&lt;/P&gt;
&lt;P&gt;Can someone help please and know how to fix it???&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 04:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625285#M107466</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-29T04:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625299#M107471</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252451"&gt;@olivera&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maybe in the event there are more timestamps and Splunk takes the wrong one or maybe there's a timezone, can you share some sampe of your events?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 07:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625299#M107471</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-27T07:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625308#M107473</link>
      <description>&lt;P&gt;Hard to say without seeing sample of your data and your configuration but there are several possible causes.&lt;/P&gt;&lt;P&gt;Most probably the timestamp is not being parsed from the event at all but is assumed to be the time of ingestion of data. But that's just a blind guess.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 09:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625308#M107473</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-27T09:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625392#M107485</link>
      <description>&lt;P&gt;I assume it's caused because of the IST in the event but I don't know how to change it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wrong time.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23155iF979A6A8AE460DA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="wrong time.jpeg" alt="wrong time.jpeg" /&gt;&lt;/span&gt;Can you help?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 08:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625392#M107485</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-28T08:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625394#M107486</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I assume it's caused because of the IST in the event but I don't know how to change it. Can you help please?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wrong time.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23156i755EA6D9DD30DE89/image-size/large?v=v2&amp;amp;px=999" role="button" title="wrong time.jpeg" alt="wrong time.jpeg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 08:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625394#M107486</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-28T08:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625395#M107487</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252451"&gt;@olivera&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;share you sample events as text not with a screenshot , so it's possible to use them.&lt;/P&gt;&lt;P&gt;is there in your events another timestamp?&lt;/P&gt;&lt;P&gt;anyway I see that you have events from Central India, probably you setted a different timezone or a wrong timestamp definition, please share the Unix:Service stanza of your props.conf.&lt;/P&gt;&lt;P&gt;It should be (with also other settings):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Unix:Service]
TIME_PREFIX = ^
TIME_FORMAT = %a %b %d %H:%M:%S %Z %Y
MAX_TIMESTAMP_LOOKAHEAD = 30&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 08:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625395#M107487</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-28T08:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625399#M107489</link>
      <description>&lt;P&gt;It seems pretty ok.&lt;/P&gt;&lt;P&gt;The event contains timestamp "9:50:51 IST". It is equivalent to "4:20:51 GMT" or "6:20:51 +2:00".&lt;/P&gt;&lt;P&gt;If the timestamp is wrong, it means your source is reporting wrong time and it's up to the source solution's admin to set the proper timestamp.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 08:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625399#M107489</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-28T08:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625407#M107490</link>
      <description>&lt;P&gt;I added the configuration and it did not change anything. Should it be in /opt/splunk/etc/deployment-apps/Splunk_TA_nix-default?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="props.conf.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23158i7902850E80716815/image-size/large?v=v2&amp;amp;px=999" role="button" title="props.conf.jpeg" alt="props.conf.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 09:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625407#M107490</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-28T09:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625408#M107491</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252451"&gt;@olivera&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this configuration must be on the forwarders used to take data and on intermediate Heavy Forwarders (if present) or on Indexers, not on the deployment-apps folder, but in the $SPLUNK_HOME/etc/apps folder.&lt;/P&gt;&lt;P&gt;How do you manage your Forwarders? are you using a Deployment Server?&lt;/P&gt;&lt;P&gt;have you an Indexers Cluster?&lt;/P&gt;&lt;P&gt;Have you intermediate heavy Forwarders?&lt;/P&gt;&lt;P&gt;Based on these information it's possible to define how to deploy this configuration, anyway, the deployment-apps folder is only used by the Deployment Server to deploy apps to forwarders, so you have to put the configuration in this folder only if you're working on the DS and you want to deploy apps to Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 09:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625408#M107491</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-28T09:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625431#M107494</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would check your user Preferences timezone.&lt;/P&gt;&lt;P&gt;Click your name in the top right &amp;gt; Preferences &amp;gt; Default System Timezone.&lt;/P&gt;&lt;P&gt;If you have it set to a timezone, it will convert the time for you.&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 17:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625431#M107494</guid>
      <dc:creator>matt8679</dc:creator>
      <dc:date>2022-12-28T17:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625567#M107516</link>
      <description>&lt;P&gt;Hello again&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I put it in the deployment apps because then I deploy it to from the DS to my universal forwarders. I meant that after the deploy of the new configuration the time of the source type still did not change. Do you have another solution? I'm a bit clueless. It's weird that only one source type's time is wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answers&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 17:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625567#M107516</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-31T17:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625568#M107517</link>
      <description>&lt;P&gt;I just found out that my time zone should be GMT +2 and it is written IST instead. Is there a way to change it in the event so the right time (which appears already in the event itself but not in the timestamp) will be parsed with this timezone?&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 17:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625568#M107517</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-31T17:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625570#M107518</link>
      <description>&lt;P&gt;Wait a minute. Your event has an IST timestamp. So it should be processed as such. If your source emits events with wrong timezone specification, it's something that should be fixed on the source. If it's telling you that something happened on midnight IST, why would you interpret it as midnight PDT, CET or any other timezone? The source is telling you that it's IST so it's interpreted as IST. Fix your source! (the problem with timezone setting on the source can be causing problems elsewhere as well, not only in your splunk).&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 20:22:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625570#M107518</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-31T20:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625573#M107519</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually my source is correct. I live in Israel and IST stands for Israel standard time but for some reason splunk interprets it as India standard time (also IST), which I believe creates the problem in the parsing of the raw text of the event.&lt;/P&gt;&lt;P&gt;I tried to configure TZ ALIAS in the props.conf but after many syntax tries it looks like it doesn't want to be applied. The props file is in an app which is on my UF's. I restarted the UF's and it still did not work.&lt;/P&gt;&lt;P&gt;What should I do to override the IST in the event?&lt;/P&gt;&lt;P&gt;pictures of props.conf:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TZ change.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23171i0D4904F88507359E/image-size/large?v=v2&amp;amp;px=999" role="button" title="TZ change.jpeg" alt="TZ change.jpeg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TZ change1.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23170iE0EC08BDF861D576/image-size/large?v=v2&amp;amp;px=999" role="button" title="TZ change1.jpeg" alt="TZ change1.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 20:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625573#M107519</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2022-12-31T20:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625576#M107520</link>
      <description>&lt;P&gt;You're right, that's probably the cause. I must say I'm a bit surprised - didn't know about such ambiguity in tz markings.&lt;/P&gt;&lt;P&gt;Anyway, your idea of TZ_ALIAS is good (don't set TZ for a fixed value - it will break your time in case of daylight saving). But it has to be placed where the timestamp is parsed from the event - indexers or HF if you're parsing on HF. UFs don't parse events (mostly).&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 23:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625576#M107520</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-31T23:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625580#M107521</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252451"&gt;@olivera&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you deployed the eabove configurations to all Universal Forwarders, Indexers and (if present) to intermediate Heavy Forwarders?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: have an Happy New Year!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 07:02:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625580#M107521</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-01T07:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625585#M107523</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You made things clear for me.&lt;/P&gt;&lt;P&gt;I have indexers and intermediate forwarders, but I configured them long ago. How can I know where the parsing of my data is? In addition, according to my knowledge, my app is only deployed to my UFs, so in what directory should I put my props.conf file? (currently in the UFs it's in ./app_name/local/props.conf)&lt;/P&gt;&lt;P&gt;In addition, I didn't understand what you meant by the TZ and daylight saving. Can you please explain?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 22:03:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625585#M107523</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2023-01-01T22:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625586#M107524</link>
      <description>&lt;P&gt;Hello again&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In what directory should I put the props.conf file in the HF and Indexers? It's confusing because it is now located in the Add-On directory and I don't deploy this Add-On to those servers.&lt;/P&gt;&lt;P&gt;Wish you luck in 2023!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 22:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625586#M107524</guid>
      <dc:creator>olivera</dc:creator>
      <dc:date>2023-01-01T22:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625596#M107525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252451"&gt;@olivera&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;To know where you are aparsing your data you can see the outputs.conf that you deployed to the UFs.&lt;/P&gt;&lt;P&gt;Anyway, if you haven't it, I hint to design a chart of your distributed architetcture, otherwise it's very difficoult to correctly deploy Add-Ons to the Forwarders.&lt;/P&gt;&lt;P&gt;About the directory,the best approach is to manually copy or (better) deploy by Deploym,ent server the same Add-On also to the Heavy Forwarder.&lt;/P&gt;&lt;P&gt;At least, about TZ and daylight saving, I suppose that he mens maintaining the original configuration.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 08:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625596#M107525</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-02T08:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting wrong time for event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625601#M107526</link>
      <description>&lt;P&gt;OK. I got a bit too far ahead of myself &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The TZ setting is only applied if there is no timezone specified within the timestamp parsed from the event so in your case this setting - even though it is set - will not apply because you have your "IST" in your time string.&lt;/P&gt;&lt;P&gt;Time is generally being parsed on the first "heavy" (based on a full installation, not the universal forwarder binary) component in event's path. So if you're sending your events straight from UF to indexers, the events are parsed on indexers (including timestamp recognition and parsing). If you're sending them from UF to HF(s) which are sending to indexers, parsing is done on HFs. And on those parsing components (in the first case - indexers, in second - on HFs) you need the TZ_ALIAS config.&lt;/P&gt;&lt;P&gt;So if you deploy your config only to UFs, it won't work since UFs don't parse events. They just read/receive them (depending on the type of input) and forward them to indexers/HFs.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 09:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-wrong-time-for-event/m-p/625601#M107526</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-02T09:06:48Z</dc:date>
    </item>
  </channel>
</rss>

