<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timezone isn't being set correctly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152747#M31096</link>
    <description>&lt;P&gt;I am not sure what I was looking at Friday as when I looked today the events' _time is correct.&lt;/P&gt;

&lt;P&gt;Thank you for your help!&lt;/P&gt;</description>
    <pubDate>Mon, 02 Mar 2015 17:18:24 GMT</pubDate>
    <dc:creator>jwinderDDS</dc:creator>
    <dc:date>2015-03-02T17:18:24Z</dc:date>
    <item>
      <title>Timezone isn't being set correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152745#M31094</link>
      <description>&lt;P&gt;I have a log file with events that look like:&lt;/P&gt;

&lt;P&gt;&amp;lt; Start &amp;gt;&lt;BR /&gt;
Timestamp: 2/27/2015 8:34:14 PM&lt;BR /&gt;
Information:&lt;BR /&gt;
Message: Refresh Scheduler Started&lt;BR /&gt;
Msg: Refresh Scheduler Started&lt;BR /&gt;
MsgType: Info&lt;BR /&gt;
Category: General&lt;BR /&gt;
Priority: -1&lt;BR /&gt;
EventId: 0&lt;BR /&gt;
Severity: Information&lt;BR /&gt;
Machine: SMLIMA&lt;BR /&gt;
App Domain: Scheduler.exe&lt;BR /&gt;
ProcessId: 13728&lt;BR /&gt;
Win32 ThreadId:28176&lt;BR /&gt;
&amp;lt; End &amp;gt;&lt;/P&gt;

&lt;P&gt;The timestamp is using UTC when the server is using -5:00. I have created a props.conf file and having it on both the Universal Forwarder and my Indexer. The stanza looks like:&lt;/P&gt;

&lt;P&gt;[lima_log]&lt;BR /&gt;
BREAK_ONLY_BEFORE_DATE = false&lt;BR /&gt;
BREAK_ONLY_BEFORE = &amp;lt; Start &amp;gt;&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;I have verified this stanza using 'splunk cmd btool props list lima_log' and it appears correct. However the event's timestamp when searching is +5:00 from what it should be. &lt;/P&gt;

&lt;P&gt;What am I doing wrong?&lt;/P&gt;

&lt;P&gt;If it matters, I am running Splunk 6.2.1.&lt;/P&gt;

&lt;P&gt;Thank you in advance,&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:00:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152745#M31094</guid>
      <dc:creator>jwinderDDS</dc:creator>
      <dc:date>2020-09-28T19:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Timezone isn't being set correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152746#M31095</link>
      <description>&lt;P&gt;You are telling Splunk that the data is in UTC! See line 4 of your stanza! You might want to set&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TZ = America/Lima
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or any other setting from the &lt;A href="http://en.wikipedia.org/wiki/List_of_tz_database_time_zones"&gt;TZ database.&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Because the Universal Forwarder does &lt;EM&gt;not&lt;/EM&gt; parse the data, you only need the &lt;CODE&gt;[lima_log]&lt;/CODE&gt; stanza on the indexer. Finally, a 6.2.1 forwarder will provide local time zone info when it sends data - so if the OS on the forwarder has the right time zone, you should not need the TZ setting at all. (Forwarders prior to Splunk 6 did not do this.)&lt;/P&gt;</description>
      <pubDate>Sat, 28 Feb 2015 20:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152746#M31095</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2015-02-28T20:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Timezone isn't being set correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152747#M31096</link>
      <description>&lt;P&gt;I am not sure what I was looking at Friday as when I looked today the events' _time is correct.&lt;/P&gt;

&lt;P&gt;Thank you for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2015 17:18:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timezone-isn-t-being-set-correctly/m-p/152747#M31096</guid>
      <dc:creator>jwinderDDS</dc:creator>
      <dc:date>2015-03-02T17:18:24Z</dc:date>
    </item>
  </channel>
</rss>

