<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarder source logs displaying in UTC Time - Need EST in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182258#M36521</link>
    <description>&lt;P&gt;Somehow this issue has cleared itself up. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Mar 2014 13:03:30 GMT</pubDate>
    <dc:creator>bcusick</dc:creator>
    <dc:date>2014-03-17T13:03:30Z</dc:date>
    <item>
      <title>forwarder source logs displaying in UTC Time - Need EST</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182254#M36517</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a forwarder that goes by EST.  My Splunk server also goes by EST.  Today I had to add a source (from a completely different server with UTC time) to my EST Splunk forwarder.&lt;/P&gt;

&lt;P&gt;How can I make _time for the logs in this source be in EST?  They can still display UTC, but I need to see them in EST for Splunk timing.&lt;/P&gt;

&lt;P&gt;I have already tried editing the props.conf to say:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mdm]
TZ = UTC
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Where mdm is the sourcetype for this source&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 19:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182254#M36517</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2014-03-11T19:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder source logs displaying in UTC Time - Need EST</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182255#M36518</link>
      <description>&lt;P&gt;Do the event timestamps include a timezone, or is the timestamp an epoch time?&lt;BR /&gt;
How did you add the new server to the forwarder, and why not add it directly to the indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 19:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182255#M36518</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-11T19:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder source logs displaying in UTC Time - Need EST</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182256#M36519</link>
      <description>&lt;P&gt;Timestamp is showing up like this in the raw log...&lt;/P&gt;

&lt;P&gt;2014-03-11 18:04:11&lt;/P&gt;

&lt;P&gt;basically all I want to do is subtract 4 hours from it. Idk how that would go if the UTC time was between midnight and 3:59AM, but I could use temporarily a method to show this time as EST (4 hours prior to what it says now)&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 19:59:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182256#M36519</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2014-03-11T19:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder source logs displaying in UTC Time - Need EST</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182257#M36520</link>
      <description>&lt;P&gt;You should try to configure splunk to recognize the correct TZ for that source, that way splunk can do all of the search time corrections for you.&lt;/P&gt;

&lt;P&gt;As for subtracting 4 hours, not a problem so long as splunk knows it is working with a time.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 20:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182257#M36520</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-11T20:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder source logs displaying in UTC Time - Need EST</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182258#M36521</link>
      <description>&lt;P&gt;Somehow this issue has cleared itself up. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 13:03:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182258#M36521</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2014-03-17T13:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder source logs displaying in UTC Time - Need EST</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182259#M36522</link>
      <description>&lt;P&gt;The indexers were probably rebooted which is required for this change to take effect.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2015 01:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-source-logs-displaying-in-UTC-Time-Need-EST/m-p/182259#M36522</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-29T01:58:58Z</dc:date>
    </item>
  </channel>
</rss>

