<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TZ Issues When Searching in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170095#M34349</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We're currently doing a pilot of Splunk. We have two servers - one is an indexer and the other a search head. We have a Linux syslog server that collects all firewall logs and forwards these to the indexer via the Universal Forwarder agent.&lt;/P&gt;

&lt;P&gt;All firewalls are set to UTC. This causes an issue when searching for events, as we're in US Eastern time. The only way to get the relevant events to show up in searches is to effectively search in the future relative to our local time (ie compute UTC for the time desired, and search on those values).&lt;/P&gt;

&lt;P&gt;I've checked and both the server and the dashboard are set to the correct time zone.&lt;/P&gt;

&lt;P&gt;Is there a way to display the time locally in the dashboard while leaving it unmodified within the index?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 19 May 2014 17:42:42 GMT</pubDate>
    <dc:creator>wbkendall</dc:creator>
    <dc:date>2014-05-19T17:42:42Z</dc:date>
    <item>
      <title>TZ Issues When Searching</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170095#M34349</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We're currently doing a pilot of Splunk. We have two servers - one is an indexer and the other a search head. We have a Linux syslog server that collects all firewall logs and forwards these to the indexer via the Universal Forwarder agent.&lt;/P&gt;

&lt;P&gt;All firewalls are set to UTC. This causes an issue when searching for events, as we're in US Eastern time. The only way to get the relevant events to show up in searches is to effectively search in the future relative to our local time (ie compute UTC for the time desired, and search on those values).&lt;/P&gt;

&lt;P&gt;I've checked and both the server and the dashboard are set to the correct time zone.&lt;/P&gt;

&lt;P&gt;Is there a way to display the time locally in the dashboard while leaving it unmodified within the index?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2014 17:42:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170095#M34349</guid>
      <dc:creator>wbkendall</dc:creator>
      <dc:date>2014-05-19T17:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: TZ Issues When Searching</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170096#M34350</link>
      <description>&lt;P&gt;You may try setting the timezone of the users to UTC, so that when they search, time range will correspond to UTC.&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2014 17:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170096#M34350</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-05-19T17:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: TZ Issues When Searching</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170097#M34351</link>
      <description>&lt;P&gt;Check out this information on how Splunk determines the TZ.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/ApplyTimezoneOffsetstotimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/ApplyTimezoneOffsetstotimestamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2014 17:53:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170097#M34351</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-05-19T17:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: TZ Issues When Searching</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170098#M34352</link>
      <description>&lt;P&gt;Thanks everyone. I finally just ended up modifying the props.conf in /opt/splunkforwarder/etc/apps/Splunk_TA-cisco-asa/local/ with this value:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host:::*]
TZ = US/Eastern
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2014 18:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TZ-Issues-When-Searching/m-p/170098#M34352</guid>
      <dc:creator>wbkendall</dc:creator>
      <dc:date>2014-05-19T18:54:23Z</dc:date>
    </item>
  </channel>
</rss>

