<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TZ Settings in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Settings/m-p/56905#M11093</link>
    <description>&lt;P&gt;You can use a regex to match a set of hosts...have you looked at &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Applytimezoneoffsetstotimestamps"&gt;specify time zones of timestamps&lt;/A&gt; in the Getting Data In manual? The example there is pretty close to your situation, if I am understanding you correctly.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2013 21:33:04 GMT</pubDate>
    <dc:creator>ChrisG</dc:creator>
    <dc:date>2013-09-06T21:33:04Z</dc:date>
    <item>
      <title>TZ Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Settings/m-p/56904#M11092</link>
      <description>&lt;P&gt;I have systems that forward logs via syslog-ng to my splunk server. Systems are in different TZ's mix of EDT and GMT my splunk server/indexer is in EDT. I have the TZ offset displayed in log entries being sent to splunk server. Two questions will splunk read TZ offset and display indexed entries in EDT without me having to put an entry for each host in the props.conf? If splunk will do automatically is there a certain postion the TZ offset has to be in? Current format: Sep  6 15:38:14 hostname +00:00&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 15:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-Settings/m-p/56904#M11092</guid>
      <dc:creator>trumpjk</dc:creator>
      <dc:date>2013-09-06T15:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: TZ Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Settings/m-p/56905#M11093</link>
      <description>&lt;P&gt;You can use a regex to match a set of hosts...have you looked at &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Applytimezoneoffsetstotimestamps"&gt;specify time zones of timestamps&lt;/A&gt; in the Getting Data In manual? The example there is pretty close to your situation, if I am understanding you correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 21:33:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-Settings/m-p/56905#M11093</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-09-06T21:33:04Z</dc:date>
    </item>
  </channel>
</rss>

