<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timezone issue with custom log time date stamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188643#M37623</link>
    <description>&lt;P&gt;Did this work? I'm facing same issue&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 12:42:11 GMT</pubDate>
    <dc:creator>k_harini</dc:creator>
    <dc:date>2018-01-17T12:42:11Z</dc:date>
    <item>
      <title>timezone issue with custom log time date stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188640#M37620</link>
      <description>&lt;P&gt;I have a log with a custom time date stamp. I am running into an issue where the index time is exactly one hour ahead of the event time stamp in the log. Could this be an issue with how I defined the date stamp in my props? I should add that the application server and the splunk server are set to use CST and have the correct system time.&lt;/P&gt;

&lt;P&gt;Here is a time stamp from the log&lt;/P&gt;

&lt;P&gt;2014-06-04T11:38:15.190 CST&lt;/P&gt;

&lt;P&gt;My props for the time stamp&lt;/P&gt;

&lt;P&gt;[prd_ufo_stats]&lt;BR /&gt;
TIME_PREFIX = ^&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 20&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%dT%H:%M:%S:%3N %Z&lt;BR /&gt;
LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;
SHOULD_LINEMERGE = False&lt;BR /&gt;
TRUNCATE = 100000&lt;BR /&gt;
KV_MODE = None&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188640#M37620</guid>
      <dc:creator>ebailey</dc:creator>
      <dc:date>2020-09-28T16:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: timezone issue with custom log time date stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188641#M37621</link>
      <description>&lt;P&gt;This doc should help fix your time stamp issue&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.1/Data/ApplyTimezoneOffsetsToTimeStamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.1/Data/ApplyTimezoneOffsetsToTimeStamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 18:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188641#M37621</guid>
      <dc:creator>jarjoh42</dc:creator>
      <dc:date>2014-06-04T18:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: timezone issue with custom log time date stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188642#M37622</link>
      <description>&lt;P&gt;Missing something- the props for this sourcetype is on the search head so I made the change and added "TZ = US/Central" and then restarted the search head with no difference.&lt;/P&gt;

&lt;P&gt;Do I need to drop %Z from the timestamp defined in props? Everything involved with the data stream is in CST so I am not sure why this is the issue other than the custom time date stamp.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 18:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188642#M37622</guid>
      <dc:creator>ebailey</dc:creator>
      <dc:date>2014-06-04T18:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: timezone issue with custom log time date stamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188643#M37623</link>
      <description>&lt;P&gt;Did this work? I'm facing same issue&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 12:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timezone-issue-with-custom-log-time-date-stamp/m-p/188643#M37623</guid>
      <dc:creator>k_harini</dc:creator>
      <dc:date>2018-01-17T12:42:11Z</dc:date>
    </item>
  </channel>
</rss>

