<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UTC Time Zone Offset Not Working for Host in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378254#M68410</link>
    <description>&lt;P&gt;Yes - many times.&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2019 16:12:06 GMT</pubDate>
    <dc:creator>ejwade</dc:creator>
    <dc:date>2019-05-20T16:12:06Z</dc:date>
    <item>
      <title>UTC Time Zone Offset Not Working for Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378252#M68408</link>
      <description>&lt;P&gt;I have a single Linux syslog stream, containing logs from multiple hosts, coming into a Splunk indexer through a TCP port - 1027. The source=tcp:1027 and sourcetype=syslog. The host is assigned using default settings, but I also have the following in place:&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[source::tcp:1027]&lt;BR /&gt;
TRANSFORMS-syslog-forwarded-hostrewrite01=syslog-forwarded-hostrewrite01&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[syslog-forwarded-hostrewrite01]&lt;BR /&gt;
DEST_KEY = MetaData:Host&lt;BR /&gt;
REGEX = ^\S+\s+[0-9]+\s+[:0-9]+\s\S+\sMessage forwarded\sfrom\s?(\S+):&lt;BR /&gt;
FORMAT = host::$1&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;There's a specific host "utc-host" that is send logs in UTC. Our indexer and users are in Pacific Time. To offset this, I created the following configuration:&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[host::utc-host]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;Unfortunately, this did not work. I did cmd btool props list to confirm the configurations were committing to Splunk's running configuration. Any tips?&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 21:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378252#M68408</guid>
      <dc:creator>ejwade</dc:creator>
      <dc:date>2019-05-17T21:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: UTC Time Zone Offset Not Working for Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378253#M68409</link>
      <description>&lt;P&gt;btool shows the configuration that will be used the next time Splunk restarts.  Did you restart Splunk after making changes to props.conf?&lt;/P&gt;</description>
      <pubDate>Sat, 18 May 2019 12:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378253#M68409</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-18T12:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: UTC Time Zone Offset Not Working for Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378254#M68410</link>
      <description>&lt;P&gt;Yes - many times.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 16:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UTC-Time-Zone-Offset-Not-Working-for-Host/m-p/378254#M68410</guid>
      <dc:creator>ejwade</dc:creator>
      <dc:date>2019-05-20T16:12:06Z</dc:date>
    </item>
  </channel>
</rss>

