<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adjusting data in GMT time zone so that splunk recognizes it in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173401#M34883</link>
    <description>&lt;P&gt;If you've setup the props.conf as mentioned in the question on Indexer/Heavy Forwarder, Splunk should attach proper/adjusted _time value to events. The timerange of the search should take the adjusted _time value and display result. Did you try to search data and what was it doing?&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2015 17:44:08 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2015-08-13T17:44:08Z</dc:date>
    <item>
      <title>Adjusting data in GMT time zone so that splunk recognizes it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173400#M34882</link>
      <description>&lt;P&gt;Is there a way to tell Splunk  what time zone the data is in so it a query run for ET automatically grabs the records with the correct adjustment for GMT? For example, if we ask for data from midnight to midnight, Splunk would automatically know to add 4 hours to adjust the time from GMT to ET.&lt;/P&gt;

&lt;P&gt;I have recognized a way on how to address the time zone disparity by editing the props as follows. But not sure whether this will work or not. The servers are sending data in GMT time zone whereas Splunk instances are on EST time zone.&lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
TZ = GMT&lt;/P&gt;

&lt;P&gt;Please let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 17:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173400#M34882</guid>
      <dc:creator>OMohi</dc:creator>
      <dc:date>2015-08-13T17:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Adjusting data in GMT time zone so that splunk recognizes it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173401#M34883</link>
      <description>&lt;P&gt;If you've setup the props.conf as mentioned in the question on Indexer/Heavy Forwarder, Splunk should attach proper/adjusted _time value to events. The timerange of the search should take the adjusted _time value and display result. Did you try to search data and what was it doing?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 17:44:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173401#M34883</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-08-13T17:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Adjusting data in GMT time zone so that splunk recognizes it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173402#M34884</link>
      <description>&lt;P&gt;You have done half the job in aligning your data so Splunk knows your events' TZ but you also have to tell it &lt;EM&gt;your&lt;/EM&gt; TZ by setting it in &lt;CODE&gt;Your Name&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Settings&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Time zone&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 19:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adjusting-data-in-GMT-time-zone-so-that-splunk-recognizes-it/m-p/173402#M34884</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-13T19:40:05Z</dc:date>
    </item>
  </channel>
</rss>

