<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can i change timestamp?(Moscow Timezone inexactness) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106596#M22431</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
i have Splunk on freebsd 8.2 and i collect logs from Cisco Ips with Splunk for Cisco IPS App(using scripted input). Trouble is in timestamps, if event occurs at present moment, i see this event on splunk through some seconds, but with timestamp like this event was one hour ago. On freebsd i have Moscow timezone and correct time, time on Ips corresponds to realtime too, but in Splunk (Manager=&amp;gt;Your account) Moscow timezone is UTC+3, but really Moscow timezone is UTC+4. This is a problem. How can i change timestamps? Or may be somebody knows another solution for this problem.&lt;BR /&gt;
P.s. i tryed to change props.conf for this app, may be i forgot something? this is my props.conf&lt;BR /&gt;
[source::/opt/splunk/etc/apps/Splunk_CiscoIPS/var/log/ips_sdee.log.192.22.97.82]&lt;BR /&gt;
[cisco_ips_syslog]&lt;BR /&gt;
TZ = AE&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:12:57 GMT</pubDate>
    <dc:creator>andrey2007</dc:creator>
    <dc:date>2020-09-28T13:12:57Z</dc:date>
    <item>
      <title>How can i change timestamp?(Moscow Timezone inexactness)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106596#M22431</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
i have Splunk on freebsd 8.2 and i collect logs from Cisco Ips with Splunk for Cisco IPS App(using scripted input). Trouble is in timestamps, if event occurs at present moment, i see this event on splunk through some seconds, but with timestamp like this event was one hour ago. On freebsd i have Moscow timezone and correct time, time on Ips corresponds to realtime too, but in Splunk (Manager=&amp;gt;Your account) Moscow timezone is UTC+3, but really Moscow timezone is UTC+4. This is a problem. How can i change timestamps? Or may be somebody knows another solution for this problem.&lt;BR /&gt;
P.s. i tryed to change props.conf for this app, may be i forgot something? this is my props.conf&lt;BR /&gt;
[source::/opt/splunk/etc/apps/Splunk_CiscoIPS/var/log/ips_sdee.log.192.22.97.82]&lt;BR /&gt;
[cisco_ips_syslog]&lt;BR /&gt;
TZ = AE&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:12:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106596#M22431</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2020-09-28T13:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can i change timestamp?(Moscow Timezone inexactness)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106597#M22432</link>
      <description>&lt;P&gt;"Moscow timezone is UTC+3, but really Moscow timezone is UTC+4"&lt;BR /&gt;
the timezone definition comes from your system TZ tables, double check that your system is up to date on the indexers and search-heads. see in /usr/share/zoneinfo/&lt;/P&gt;

&lt;P&gt;on linux you can try any timezone conversion of the current time with&lt;BR /&gt;
&lt;CODE&gt;date; export TZ=AE; date&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2013 16:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106597#M22432</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-31T16:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can i change timestamp?(Moscow Timezone inexactness)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106598#M22433</link>
      <description>&lt;P&gt;Yes, my system is up to date and with correct time, for testing i have one Splunk instance.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2013 17:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-change-timestamp-Moscow-Timezone-inexactness/m-p/106598#M22433</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2013-01-31T17:09:26Z</dc:date>
    </item>
  </channel>
</rss>

