<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to change timezone of the logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354766#M64897</link>
    <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
We will get to the bottom of this!&lt;/P&gt;

&lt;P&gt;Run this over the last 15 minutes and paste the first few rows of the table.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;your search&amp;gt; |eval indextime=strftime(_indextime,"%Y-%m-%d %H:%M:%S")|table indextime _time _raw |sort -indextime&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Dec 2017 20:38:36 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2017-12-21T20:38:36Z</dc:date>
    <item>
      <title>Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354750#M64881</link>
      <description>&lt;P&gt;We have a host sending logs in UTC timezone and we want to display it in US/Central timezone.&lt;BR /&gt;
I have added the below configuration in the props.conf file on our indexer, but this does not help.&lt;/P&gt;

&lt;P&gt;[host::(name of the host)]&lt;BR /&gt;
TZ = US/Central&lt;/P&gt;

&lt;P&gt;Where do I need to edit the props.conf file? Search head? Indexer? Deployment server?&lt;/P&gt;

&lt;P&gt;Can somebody please assist?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 20:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354750#M64881</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-20T20:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354751#M64882</link>
      <description>&lt;P&gt;Its generally a good idea to index the events in the correct timezone, or else you are starting down a painful road.&lt;/P&gt;

&lt;P&gt;If you want to see these in your local timezone - update your user preferences to specify which TZ you are in, and splunk will adjust how it renders them for you.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 20:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354751#M64882</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T20:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354752#M64883</link>
      <description>&lt;P&gt;Sorry  but what do you mean by the below statement?&lt;/P&gt;

&lt;P&gt;"update your user preferences to specify which TZ you are in, and splunk will adjust how it renders them for you."&lt;/P&gt;

&lt;P&gt;How do I achieve it?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 20:49:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354752#M64883</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-20T20:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354753#M64884</link>
      <description>&lt;P&gt;From the Splunk UI, click your username in the top right bar.&lt;BR /&gt;
Select account Settings.&lt;BR /&gt;
Set your timezone.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 20:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354753#M64884</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T20:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354754#M64885</link>
      <description>&lt;P&gt;It is already set to Central still we see the logs in UTC.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 21:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354754#M64885</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-20T21:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354755#M64886</link>
      <description>&lt;P&gt;Can you post an example log message including the timestamp from the original event? &lt;BR /&gt;
What timezone is the originating server in?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 21:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354755#M64886</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T21:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354756#M64887</link>
      <description>&lt;P&gt;URL: /restconnect/connect/users/2770........&lt;/P&gt;

&lt;P&gt;Timestamp: 2017-12-20T15:28:55.449Z &lt;/P&gt;

&lt;P&gt;_time: 2017-12-20 09:28:55.449&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 21:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354756#M64887</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-20T21:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354757#M64888</link>
      <description>&lt;P&gt;I am confused, If I understand your response, the raw log says 15:28:55Z (ie UTC)&lt;BR /&gt;
but _time (by which i assume you mean the timestamp Splunk is reporting) says 09:28:55 is correctly adjusted -6 hours?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 21:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354757#M64888</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T21:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354758#M64889</link>
      <description>&lt;P&gt;You are correct.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 22:05:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354758#M64889</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-20T22:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354759#M64890</link>
      <description>&lt;P&gt;Cool, Glad its sorted. &lt;BR /&gt;
Please accept one of the answers/upvote if I helped you - It helps future visitors know that we got to the bottom of it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 22:16:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354759#M64890</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T22:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354760#M64891</link>
      <description>&lt;P&gt;No its not sorted, we want to make the _time as 15:28:55Z  instead of 09:28:55, &lt;BR /&gt;
The timestamp and _time should be same and in Central timezone.please help.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 22:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354760#M64891</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-20T22:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354761#M64892</link>
      <description>&lt;P&gt;Ok, then I am still confused &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Your original question said:&lt;BR /&gt;
"We have a host sending logs in UTC timezone and we want to display it in US/Central timezone."&lt;/P&gt;

&lt;P&gt;Thats exactly what you have right now.&lt;/P&gt;

&lt;P&gt;Splunk won't (can't) update the _raw log data, which seems to be what you are asking.&lt;/P&gt;

&lt;P&gt;The only way i can reason this out in my mind, is that you are saying the time in the original log data is wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 22:45:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354761#M64892</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T22:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354762#M64893</link>
      <description>&lt;P&gt;What if you set your user preferences to UTC - this would display both values as 15:28? (but would probably screw up any other events)&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 22:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354762#M64893</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-20T22:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354763#M64894</link>
      <description>&lt;P&gt;I would like to re frame here,&lt;/P&gt;

&lt;P&gt;Timestamp: 2017-12-20T15:28:55.449Z (This is already displayed as CST)&lt;/P&gt;

&lt;P&gt;_time: 2017-12-20 09:28:55.449 (This is UTC)&lt;/P&gt;

&lt;P&gt;I want to convert _time to CST.&lt;/P&gt;

&lt;P&gt;I hope it helps now.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 17:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354763#M64894</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-21T17:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354764#M64895</link>
      <description>&lt;P&gt;I'm sorry dude, but your wrong on both fronts.&lt;/P&gt;

&lt;P&gt;The Z in the timestamp specifically means the time recorded is in ZULU time, or UTC. Not CST&lt;BR /&gt;
&lt;A href="https://stackoverflow.com/questions/9706688/what-does-the-z-mean-in-unix-timestamp-120314170138z"&gt;https://stackoverflow.com/questions/9706688/what-does-the-z-mean-in-unix-timestamp-120314170138z&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Even if that was not the case..  UTC is not behind CST. The uk is 6 hours &lt;EM&gt;ahead&lt;/EM&gt; of central US.&lt;/P&gt;

&lt;P&gt;This means that the event was recorded at 3:28 in the afternoon UTC - regardless of where you happen to be - Since you are  (i assume) in Central USA, 3:28 PM in the uk, is 09:28AM where you are.&lt;/P&gt;

&lt;P&gt;I don't think you have a config issue - we can even prove it if you like.&lt;BR /&gt;
Do a realtime search for these events - My 50cent bet says you will see events popping into the right side of your timeline, meaning they are arriving "now" - the raw log message will say 19:35(ish if your online when i send this) but your _time will be 13:35 which i think is the time where you are right now.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 19:34:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354764#M64895</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-21T19:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354765#M64896</link>
      <description>&lt;P&gt;This is so confusing, not sure what the issue is.&lt;/P&gt;

&lt;P&gt;My raw log says   timestamp:     2017-12-21T14:06:08.893Z&lt;/P&gt;

&lt;P&gt;My _time says 21/12/2017 08:06:08.893&lt;/P&gt;

&lt;P&gt;My machine is set to CST.&lt;/P&gt;

&lt;P&gt;User preferences is also set to CST.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 20:13:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354765#M64896</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-21T20:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354766#M64897</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
We will get to the bottom of this!&lt;/P&gt;

&lt;P&gt;Run this over the last 15 minutes and paste the first few rows of the table.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;your search&amp;gt; |eval indextime=strftime(_indextime,"%Y-%m-%d %H:%M:%S")|table indextime _time _raw |sort -indextime&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 20:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354766#M64897</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-21T20:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354767#M64898</link>
      <description>&lt;P&gt;Ok so if I search for last 15 mins, I do not see any logs.&lt;/P&gt;

&lt;P&gt;But when I search for today, this is what I see, image uploaded&lt;/P&gt;

&lt;P&gt;&lt;A href="https://ibb.co/d5469m"&gt;https://ibb.co/d5469m&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 20:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354767#M64898</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-21T20:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354768#M64899</link>
      <description>&lt;P&gt;Do you still have this in props?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host::(name of the host)]
TZ = US/Centra
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also - Where is a.) your splunk server b.) your server producing the logs - Are they both systems you manage, or are they remotely hosted?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 21:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354768#M64899</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-21T21:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to change timezone of the logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354769#M64900</link>
      <description>&lt;P&gt;[host::(name of the host)]&lt;BR /&gt;
 TZ = US/Centra&lt;BR /&gt;
I removed this from my logs today. Do you want me to add them? If yes, then where search head, indexer or deployment?&lt;/P&gt;

&lt;P&gt;a) By splunk server if you mean search head, indexer or deployment server then yes I manage them.&lt;/P&gt;

&lt;P&gt;b) the server producing logs is remotely hosted&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 21:15:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-change-timezone-of-the-logs/m-p/354769#M64900</guid>
      <dc:creator>ppanchal</dc:creator>
      <dc:date>2017-12-21T21:15:52Z</dc:date>
    </item>
  </channel>
</rss>

