<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TZ offset in props.conf not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82194#M16993</link>
    <description>&lt;P&gt;My splunk forwarders are light forwarders, so I am setting my timezone offset for my web servers with the following on my splunk indexer, in my default app si_idx (/opt/splunk/etc/apps/si_idx/default/props.conf) I place the following:&lt;/P&gt;

&lt;P&gt;[host::web*]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;My web servers are logging in UTC, the event data is as follows: &lt;BR /&gt;
10:53:24.699    &lt;/P&gt;

&lt;P&gt;2011-09-27 10:53:24,699 [27] DEBUG SPIN.Wholesale.Presentation.BL.Managers.ChannelRequestManager Channel d3ffba61-0f1a-4e4f-8536-24593a89090b requested at: 27/09/2011 10:53:24&lt;/P&gt;

&lt;P&gt;and I wish the splunk timestamp to be one hour later (Europe/London).&lt;BR /&gt;
The entry in props.conf above does not work when I restart splunk, the splunk timestamp is still in UTC. Where am I going wrong?&lt;BR /&gt;
thanks, conor&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:54:51 GMT</pubDate>
    <dc:creator>conorglynn</dc:creator>
    <dc:date>2020-09-28T09:54:51Z</dc:date>
    <item>
      <title>TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82194#M16993</link>
      <description>&lt;P&gt;My splunk forwarders are light forwarders, so I am setting my timezone offset for my web servers with the following on my splunk indexer, in my default app si_idx (/opt/splunk/etc/apps/si_idx/default/props.conf) I place the following:&lt;/P&gt;

&lt;P&gt;[host::web*]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;My web servers are logging in UTC, the event data is as follows: &lt;BR /&gt;
10:53:24.699    &lt;/P&gt;

&lt;P&gt;2011-09-27 10:53:24,699 [27] DEBUG SPIN.Wholesale.Presentation.BL.Managers.ChannelRequestManager Channel d3ffba61-0f1a-4e4f-8536-24593a89090b requested at: 27/09/2011 10:53:24&lt;/P&gt;

&lt;P&gt;and I wish the splunk timestamp to be one hour later (Europe/London).&lt;BR /&gt;
The entry in props.conf above does not work when I restart splunk, the splunk timestamp is still in UTC. Where am I going wrong?&lt;BR /&gt;
thanks, conor&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82194#M16993</guid>
      <dc:creator>conorglynn</dc:creator>
      <dc:date>2020-09-28T09:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82195#M16994</link>
      <description>&lt;P&gt;We have managed to sort out the times on our log4j clients at source, but I am still having problems getting the IIS logs to offset correctly, I have placed the following in props.conf on the Indexer but it having no effect:&lt;/P&gt;

&lt;P&gt;[IIS]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;does anybody have any info on getting IIS logs to offset to the correct Timezone on the indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 16:17:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82195#M16994</guid>
      <dc:creator>conorglynn</dc:creator>
      <dc:date>2011-09-27T16:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82196#M16995</link>
      <description>&lt;P&gt;We do it by source which works fine..&lt;BR /&gt;
[source::\\SERVERNAME\prod-iislogs\...\...\u_ex*.log]&lt;BR /&gt;
TZ = GMT&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 17:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82196#M16995</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2011-09-27T17:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82197#M16996</link>
      <description>&lt;P&gt;thanks rnavis,&lt;BR /&gt;
yes, I changed to setting the TZ by source in props.conf and it works just fine, for some reason the same thing did not work by host or sourcetype for me.&lt;BR /&gt;
anyway, all well now, thanks, conor&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2011 10:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82197#M16996</guid>
      <dc:creator>conorglynn</dc:creator>
      <dc:date>2011-09-28T10:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82198#M16997</link>
      <description>&lt;P&gt;After trial and error, it seems to work when I specify it without any spaces and then restart the indexer. Using $SPLUNK_HOME/etc/system/local/props.conf in 4.3.6 version:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::*\\mydata\\Log*]
TZ=UTC
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 22 May 2013 17:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82198#M16997</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2013-05-22T17:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82199#M16998</link>
      <description>&lt;P&gt;I seem to be having the same issue. Setting TZ via [host::myhost] is not affecting while using the [source::mysource] is working. Were you able to get it to work using a host stanza?&lt;BR /&gt;
PS. I am using Splunk 5.0.10&lt;/P&gt;</description>
      <pubDate>Sun, 16 Nov 2014 16:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82199#M16998</guid>
      <dc:creator>yuvalba</dc:creator>
      <dc:date>2014-11-16T16:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82200#M16999</link>
      <description>&lt;P&gt;I noticed the same thing in splunk 6.1* flavors. I recall it was even reproducible while defining the sourcetype in the data inputs UI. If not done already, I would encourage you to create a support ticket. It's possible this is not a known issue.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Nov 2014 17:51:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82200#M16999</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2014-11-16T17:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82201#M17000</link>
      <description>&lt;P&gt;Thank you, I was just banging my head on a data source with TZ command, I usually match on sourcetype and typically it works, in this case it did not (I think due to the fact that I was overriding the sourcetype field) matching this field on source did the trick for me.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 20:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82201#M17000</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2015-05-26T20:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82202#M17001</link>
      <description>&lt;P&gt;This is still an issue in version 6.5.2. If the sourcetype is defined in inputs and not reassigned in props/transforms it works fine.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 03:06:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82202#M17001</guid>
      <dc:creator>ejenson_splunk</dc:creator>
      <dc:date>2017-07-13T03:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: TZ offset in props.conf not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82203#M17002</link>
      <description>&lt;P&gt;I'm having the same issue in 7.3.2.  System is logging in US/Eastern, Splunk is UTC.  My props is based on source.  Applied it on HF, and Indexer, no change to time setting.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 21:41:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-offset-in-props-conf-not-working/m-p/82203#M17002</guid>
      <dc:creator>esalesapns2</dc:creator>
      <dc:date>2019-11-13T21:41:42Z</dc:date>
    </item>
  </channel>
</rss>

