<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we adjust our firewall's timezone? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297705#M56336</link>
    <description>&lt;P&gt;I am confused. - Lets work in UTC time only (no daylight saving)&lt;/P&gt;

&lt;P&gt;Current UTC time as I type this is: 11:53&lt;BR /&gt;
Your Firewall is now set to UTC? - Therefore the timestamps on your firewall should be 11:53?&lt;BR /&gt;
However, your log indicates that the current time is 04:21 (which is 7 hours behind UTC)&lt;BR /&gt;
You have imported the logs, and set the TZ in the props to tell splunk you are using UTC&lt;/P&gt;

&lt;P&gt;In your user account settings - what is your splunk user's timezone set to?&lt;BR /&gt;
Infact, what is your splunk servers timezone set to?&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2017 11:56:21 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2017-10-17T11:56:21Z</dc:date>
    <item>
      <title>How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297695#M56326</link>
      <description>&lt;P&gt;Hi All, Currently we are facing an issue with time stamp for an firewall logs. We could see the logs are coming into splunk with a time difference of 3 hours. We have 5 heavy forwarder instance as intermediate forwarder and this firewall log is read from this 5 HF instance which is configured as syslogs server. The splunk reads the logs from these 5 HF instance and then ingest the data into indexer.&lt;/P&gt;

&lt;P&gt;inputs.conf detail :&lt;BR /&gt;
[monitor:///opt/syslogs/mguard/.../mguard.log*] &lt;BR /&gt;
index=fw&lt;BR /&gt;
sourcetype=mguard:network:log &lt;BR /&gt;
host_segment = 4&lt;/P&gt;

&lt;P&gt;10/13/17&lt;BR /&gt;
10:35:57.000 AM &lt;BR /&gt;
Oct 13 10:35:57 test01.xxx.com 1,2017/10/13 10:35:57,007257000034869,TRAFFIC,start,0,2017/10/13 10:35:57,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-xxxx,,,ssl,vsys1,trust,xxxx,ethernet1/2,ethernet1/1,Splunk,2017/10/13 10:35:57,761997,1,51475,8089,0,0,0x104000,tcp,allow,416,350,66,4,2017/10/13 10:35:56,0,any,0,70021120,0x0,x.0.0.0-x.255.255.255,United States,0,3,1,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;BR /&gt;
eventtype = nix-all-logs eventtype = pan network host = test01.xxx.com source = /opt/syslogs/mguard/test01.xxx.com/mguard.log sourcetype = mguard:network:log tag = network timeendpos = 16 timestartpos = 0&lt;/P&gt;

&lt;P&gt;Current EDT time is 1:40 PM and logs are coming into splunk with a timestamp of &lt;BR /&gt;
10:35:57.000 AM, so need to adjust the time zone by 3 hours to match the current EDT time.&lt;/P&gt;

&lt;P&gt;Kindly guide me how to adjust this time zone by 3 hours in Splunk&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 19:54:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297695#M56326</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T19:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297696#M56327</link>
      <description>&lt;P&gt;Your firewall logs don't appear to specify a timezone offset, so Splunk will assume the timestamps are in UTC.&lt;/P&gt;

&lt;P&gt;1.) Are you sure your firewall has the correct time?&lt;BR /&gt;
2.) Does your firewall know what TZ its in?&lt;BR /&gt;
3.) Can you amend your firewalls logs to include a TZ?&lt;BR /&gt;
4.) Maybe you can "fix" this on the syslog server? - In my experience its always better to try and fix this as close to the source as possible.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 20:00:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297696#M56327</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-13T20:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297697#M56328</link>
      <description>&lt;P&gt;Hi Nickhillscpl, thanks for your effort on this.  As I had commented earlier , both the HF instance and syslogs details are configured in the same node. and i had also included the TZ in props.conf file  for the sourcetype mguard:network:log  but it done fix the issue, we could see there is a difference of 3 hours between the current time and index time.  Below props.conf has been deployed at HF instance from where the splunk reads the log and ingest into indexer. &lt;/P&gt;

&lt;P&gt;Props.conf: &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = EDT &lt;/P&gt;

&lt;P&gt;Kindly guide me how to adjust this time zone by 3 hours in Splunk&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 20:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297697#M56328</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T20:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297698#M56329</link>
      <description>&lt;P&gt;I am not sure EDT is a valid TZ value, have you tried EST?&lt;BR /&gt;
Did you restart the HF after updating the props file?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 20:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297698#M56329</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-13T20:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297699#M56330</link>
      <description>&lt;P&gt;actually - try "US/Eastern" or "EST5EDT" which (if works) will account for daylight saving&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 20:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297699#M56330</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-13T20:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297700#M56331</link>
      <description>&lt;P&gt;hi nickhillspci, thanks for your effort on this,  we have customized app and its pushed via deployer, in forwardmanagement we had mentioned  enable the app /restart splunkd. so it should have been restarted when we execute splunk reload deploy-server. &lt;/P&gt;

&lt;P&gt;Do I need to change the props.conf like this &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = EST5EDT&lt;/P&gt;

&lt;P&gt;Below event detail are taken by keeping the time frame for last 24 hrs and current time in pennsylvania is 5:00 PM.&lt;BR /&gt;
 But in the event you can see the index time is 3 hours behind the current time. So I need to fix this to match the current time.&lt;/P&gt;

&lt;P&gt;Event details:&lt;/P&gt;

&lt;P&gt;10/13/17&lt;BR /&gt;
2:00:15.000 PM &lt;BR /&gt;
Oct 13 14:00:15 test01.xxx.com1,2017/10/13 14:00:14,007257000034869,TRAFFIC,end,0,2017/10/13 14:00:14,10.x.x.x,51.x.x.x.x,0.0.0.0,0.0.0.0,trust-test01,,,incomplete,vsys1,trust,test01,ethernet1/2,ethernet1/1,Splunk,2017/10/13 14:00:14,770183,1,57307,443,0,0,0x4064,tcp,allow,132,132,0,2,2017/10/13 14:00:06,3,any,0,70039854,0x0,10.0.0.0-10.255.255.255,United States,0,2,0,aged-out,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297700#M56331</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T21:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297701#M56332</link>
      <description>&lt;P&gt;Hi Nickhillspci, I had tried below props.conf stanza and it worked perfectly thank for your much need effort on this issue.&lt;/P&gt;

&lt;P&gt;Props.conf &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = GMT &lt;/P&gt;

&lt;P&gt;Now I could see the index time is matching the current time of EDT.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 12:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297701#M56332</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-16T12:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297702#M56333</link>
      <description>&lt;P&gt;Hi Hemnaath, that's great news. If this has solved the issue can you accept the answer so its marked as resolved.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 13:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297702#M56333</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-16T13:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297703#M56334</link>
      <description>&lt;P&gt;Hi Nickhillscpl,  I have an issue now, data are not getting ingested into splunk from mguard logs, i am not sure whether it was happened due to above props.conf stanza. If that is not a case then kindly let me know what are trouble shooting steps should I need to follow to analysis the issue. &lt;/P&gt;

&lt;P&gt;thanks in advance.  &lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 17:32:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297703#M56334</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-16T17:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297704#M56335</link>
      <description>&lt;P&gt;Hi Nickhillscpl, Hey the issue is not fixed, we are facing same  time stamp issue for firewall logs. Again the logs are coming into splunk with a time difference of 3 hours. The firewall team has re-configured this device and the timezone on the device is now UTC . So I had updated the below stanza details in props.conf  and after updating props.conf in the customized app , event data are not getting ingested into splunk.&lt;/P&gt;

&lt;P&gt;[mgaurd:network:log]&lt;BR /&gt;
TZ = UTC &lt;/P&gt;

&lt;P&gt;Event details &lt;BR /&gt;
10/17/17&lt;BR /&gt;
4:21:56.000 AM&lt;BR /&gt;&lt;BR /&gt;
Oct 17 04:21:56 test01.xxx.com 1,2017/10/17 04:21:55,007257000034869,TRAFFIC,start,0,2017/10/17 04:21:55,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-xxxx,,,ssl,vsys1,trust,xxxx,ethernet1/2,ethernet1/1,Splunk,2017/10/17 04:21:55,229798,1,49472,10194,0,0,0x104041,tcp,allow,838,653,185,6,2017/10/17 04:21:55,0,computer-and-internet-info,0,70586295,0x0,10.x.x.x,10.x.x.x,United States,0,4,2,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;BR /&gt;
host =  test01.xxx.com source = /opt/syslogs/mguard/test01.xxx.com/mguard.log sourcetype =  mguard:network:log&lt;/P&gt;

&lt;P&gt;Current time in pennsylvania is 7:22 AM and if you can see the event data indexed time is 4:21 AM almost 3 hours difference its getting logged in. &lt;/P&gt;

&lt;P&gt;Exact Two Problem: &lt;/P&gt;

&lt;P&gt;1 )When the above  the props.conf, is added into app, then the firewall data are not getting ingested into splunk.&lt;BR /&gt;
 2) Similarly when the above props.conf is removed from the customized app, then the firewall data are getting indexed into splunk but with a time difference of 3 hours.&lt;/P&gt;

&lt;P&gt;Kindly guide me on this to fix the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 11:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297704#M56335</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T11:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297705#M56336</link>
      <description>&lt;P&gt;I am confused. - Lets work in UTC time only (no daylight saving)&lt;/P&gt;

&lt;P&gt;Current UTC time as I type this is: 11:53&lt;BR /&gt;
Your Firewall is now set to UTC? - Therefore the timestamps on your firewall should be 11:53?&lt;BR /&gt;
However, your log indicates that the current time is 04:21 (which is 7 hours behind UTC)&lt;BR /&gt;
You have imported the logs, and set the TZ in the props to tell splunk you are using UTC&lt;/P&gt;

&lt;P&gt;In your user account settings - what is your splunk user's timezone set to?&lt;BR /&gt;
Infact, what is your splunk servers timezone set to?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 11:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297705#M56336</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-17T11:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297706#M56337</link>
      <description>&lt;P&gt;EDIT: I removed my error from the last comment &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Wait. I over thought that. &lt;BR /&gt;
The numbers in my last comment are rubbish. But my two questions remain. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 12:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297706#M56337</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-17T12:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297707#M56338</link>
      <description>&lt;P&gt;Hi Nickhillscpl, thanks for getting into this problem, Yes I had checked the time set on both Heavy forwarder instance and indexer instances " Tue Oct 17 08:11:54 EDT 2017"  and time zone for my user id in access control is defined as None.  Kindly let me know where will be the issue now, not sure how to fix this issue. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 12:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297707#M56338</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T12:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297708#M56339</link>
      <description>&lt;P&gt;Ok, so to summarize (because I totally confused myself earlier &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  - &lt;BR /&gt;
Your servers are in EDT, your browser is in EDT. So far so good.&lt;/P&gt;

&lt;P&gt;Your firewall is sending events in (currently) UTC-7 So according to: &lt;A href="https://en.wikipedia.org/wiki/List_of_tz_database_time_zones" target="_blank"&gt;https://en.wikipedia.org/wiki/List_of_tz_database_time_zones&lt;/A&gt;&lt;BR /&gt;
You should try &lt;CODE&gt;TZ = MST7MDT&lt;/CODE&gt; which will offset 7 hours, and account for DST&lt;/P&gt;

&lt;P&gt;Out of interest - where is the firewall geographically located?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:19:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297708#M56339</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-09-29T16:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297709#M56340</link>
      <description>&lt;P&gt;thanks nickhillscpl, do you want me to update the props.conf stanza like this in HF instance.&lt;/P&gt;

&lt;P&gt;Props.conf&lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = MST7MDT &lt;/P&gt;

&lt;P&gt;What it mean I did not understand this time zone .&lt;BR /&gt;
Could not find the device location as the device appears to be on Azure cloud, by executing the tracert test01 from HF instances. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 13:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297709#M56340</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T13:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297710#M56341</link>
      <description>&lt;P&gt;&lt;A href="https://simple.wikipedia.org/wiki/Mountain_Time_Zone"&gt;https://simple.wikipedia.org/wiki/Mountain_Time_Zone&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 13:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297710#M56341</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-17T13:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297711#M56342</link>
      <description>&lt;P&gt;hmm thanks so I will update the above props.conf stanza with the Mountain Time zone in HF instances.  And validate whether its working or not. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 13:53:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297711#M56342</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T13:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297712#M56343</link>
      <description>&lt;P&gt;hi nickhillscpl thanks for your effort now I could see time difference of 1 hour between the indexed time and the current time. &lt;/P&gt;

&lt;P&gt;Props.conf&lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = MST7MDT&lt;/P&gt;

&lt;P&gt;Event data: &lt;/P&gt;

&lt;P&gt;10/17/17&lt;BR /&gt;
9:18:14.000 AM&lt;BR /&gt;&lt;BR /&gt;
Oct 17 07:18:14 test01.xxx.com 1,2017/10/17 07:18:14,007257000034869,TRAFFIC,start,0,2017/10/17 07:18:14,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-xxxx,,,ssl,vsys1,trust,xxxx,ethernet1/2,ethernet1/1,Splunk,2017/10/17 07:18:14,238722,1,50351,10194,0,0,0x104041,tcp,allow,946,707,239,8,2017/10/17 07:18:14,0,computer-and-internet-info,0,70602352,0x0,10.x.x.x,10.x.x.x,United States,0,5,3,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;BR /&gt;
host =  test01.xxx.com source = /opt/syslogs/mguard/test01.xxx.com/mguard.log sourcetype =  mguard:network:log&lt;/P&gt;

&lt;P&gt;Current time in Pennsylvania  is 10:18 AM .&lt;/P&gt;

&lt;P&gt;difference of 1 hour between the indexed time and the current time. &lt;/P&gt;

&lt;P&gt;kindly guide me to fix this .&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:22:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297712#M56343</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T14:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297713#M56344</link>
      <description>&lt;P&gt;Hi Nickhillscpl, could please guide me on this .&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297713#M56344</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T14:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: How can we adjust our firewall's timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297714#M56345</link>
      <description>&lt;P&gt;Where is the firewall? - in the world?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-we-adjust-our-firewall-s-timezone/m-p/297714#M56345</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-17T14:59:28Z</dc:date>
    </item>
  </channel>
</rss>

