<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defining time zone (TZ) value for Manual Host Extraction for syslog input in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458414#M79228</link>
    <description>&lt;P&gt;I eventually figured it out... it just always seems to take some fiddling... the syntax for this doesn't always match what you can do in inputs.conf it seems. Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 25 Aug 2019 17:15:38 GMT</pubDate>
    <dc:creator>itradeclayton</dc:creator>
    <dc:date>2019-08-25T17:15:38Z</dc:date>
    <item>
      <title>Defining time zone (TZ) value for Manual Host Extraction for syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458411#M79225</link>
      <description>&lt;P&gt;HI All,&lt;/P&gt;

&lt;P&gt;I have created an inputs stanza for syslog input and created a manual host override using transforms. I tried to change the TZ value per host but it is not working. However, it works fine, if used per source type.&lt;BR /&gt;
Kindly suggest how to fix&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Inputs.conf&lt;/STRONG&gt;  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  [tcp://&amp;lt;port&amp;gt;]
    sourcetype = &amp;lt;custom_sourcetype&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Props.conf&lt;/STRONG&gt;   &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [host::ABC]
    TZ = UTC
    [host::DEF]
    TZ = Europe/London
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Sep 2018 22:15:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458411#M79225</guid>
      <dc:creator>akshatj2</dc:creator>
      <dc:date>2018-09-14T22:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Defining time zone (TZ) value for Manual Host Extraction for syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458412#M79226</link>
      <description>&lt;P&gt;Did you ever figure this out? It's driving me crazy. I can't change all my "syslog" sourcetypes to the same timezone. I need to change by host or source etc. &lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2019 16:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458412#M79226</guid>
      <dc:creator>itradeclayton</dc:creator>
      <dc:date>2019-08-25T16:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Defining time zone (TZ) value for Manual Host Extraction for syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458413#M79227</link>
      <description>&lt;P&gt;Could you tell me where are you trying to define the TZ value&lt;/P&gt;

&lt;P&gt;i would assume you have a heavy forwarder in place which is used to receive messages from syslog.&lt;/P&gt;

&lt;P&gt;If yes you can try to set TZ value in your HF it should work. Also, make sure that splunk is taking time from the logs by setting appropriate Time Prefix and Time Format.&lt;/P&gt;

&lt;P&gt;If still does not work can you give me more details so I can try to help you.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2019 17:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458413#M79227</guid>
      <dc:creator>akshatj2</dc:creator>
      <dc:date>2019-08-25T17:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Defining time zone (TZ) value for Manual Host Extraction for syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458414#M79228</link>
      <description>&lt;P&gt;I eventually figured it out... it just always seems to take some fiddling... the syntax for this doesn't always match what you can do in inputs.conf it seems. Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2019 17:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defining-time-zone-TZ-value-for-Manual-Host-Extraction-for/m-p/458414#M79228</guid>
      <dc:creator>itradeclayton</dc:creator>
      <dc:date>2019-08-25T17:15:38Z</dc:date>
    </item>
  </channel>
</rss>

