<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timestamp setting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43707#M8162</link>
    <description>&lt;P&gt;the former please. Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 30 Aug 2012 16:06:59 GMT</pubDate>
    <dc:creator>Ant1D</dc:creator>
    <dc:date>2012-08-30T16:06:59Z</dc:date>
    <item>
      <title>Timestamp setting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43704#M8159</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;I have an index where each event starts with a UTC timestamp. It is using this UTC timestamp for the _time field. Instead I would like for all events in this index to use the Splunk server timezone for the _time field. How can I configure Splunk to do this?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2012 15:29:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43704#M8159</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-08-24T15:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp setting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43705#M8160</link>
      <description>&lt;P&gt;are you saying you want the timestamp interpreted as if it were in the Splunk indexer timezone instead of in UTC, or do you mean you want to display the (UTC) timestamp in the Splunk server timezone?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2012 16:13:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43705#M8160</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-08-24T16:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp setting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43706#M8161</link>
      <description>&lt;P&gt;You could try to assign the timezone in your props.conf&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2012 20:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43706#M8161</guid>
      <dc:creator>allamiro</dc:creator>
      <dc:date>2012-08-24T20:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp setting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43707#M8162</link>
      <description>&lt;P&gt;the former please. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2012 16:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43707#M8162</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-08-30T16:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp setting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43708#M8163</link>
      <description>&lt;P&gt;The answer to this question can be found here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/57543/splunk-displaying-events-with-the-correct-timezone"&gt;http://splunk-base.splunk.com/answers/57543/splunk-displaying-events-with-the-correct-timezone&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2012 08:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-setting/m-p/43708#M8163</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-05T08:39:33Z</dc:date>
    </item>
  </channel>
</rss>

