<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2 Different Timezones being interpreted with the same IIS log file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/2-Different-Timezones-being-interpreted-with-the-same-IIS-log/m-p/503210#M85731</link>
    <description>&lt;P&gt;As with many folks, my IIS logs are setup to run with GMT timestamps. I have setup "TZ=GMT" on the sourcetype setup for my IIS logs, set in the indexer under props.conf.&lt;/P&gt;

&lt;P&gt;I have multiple IIS servers using the same source type. For most of my servers, all is well and I see that Splunk is converting the timezone to my local timezone (Pacific) based on my settings. However, there are a few servers that I see Splunk is interpretting 2 different timezones, see below:&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;&lt;STRONG&gt;10/21/19&lt;BR /&gt;
7:35:55.000 AM&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;2019-10-21 07:35:55 10.1.24.88 GET /api/..snip.. - 80 - 10.1.24.81 - - 200 0 0 6&lt;BR /&gt;
host = V-WEB-PA-2-P **source = C:\inetpub\logs\logfiles\W3SVC22\u_ex191021.log&lt;/EM&gt;* sourcetype = ms:iis:default*&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;10/21/19&lt;BR /&gt;
7:35:54.000 AM&lt;/STRONG&gt;    &lt;/P&gt;

&lt;P&gt;*2019-10-21 14:35:54 10.1.24.88 POST /api/..snip.. - 80 - 10.1.24.88 - - 200 0 0 2&lt;/P&gt;

&lt;H2&gt;host = V-WEB-PA-2-P &lt;STRONG&gt;source = C:\inetpub\logs\logfiles\W3SVC22\u_ex191021.log&lt;/STRONG&gt; sourcetype = ms:iis:default*&lt;/H2&gt;

&lt;P&gt;Splunk is interpreting log entries with "7:35:xx" and 14:35:xx" as both IIS logs that have happened at 7:35:xx Localtime. The correct and expected interpretation is only log entries with "14:35:xx"  should be interpreted that way. &lt;/P&gt;

&lt;P&gt;You will notice that the same file is being used to make the two interpretations. &lt;/P&gt;

&lt;P&gt;Can anyone please point me in the direction of where I may have mis-configured Splunk, or why this is happening? &lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:34:58 GMT</pubDate>
    <dc:creator>derekho55</dc:creator>
    <dc:date>2020-09-30T02:34:58Z</dc:date>
    <item>
      <title>2 Different Timezones being interpreted with the same IIS log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/2-Different-Timezones-being-interpreted-with-the-same-IIS-log/m-p/503210#M85731</link>
      <description>&lt;P&gt;As with many folks, my IIS logs are setup to run with GMT timestamps. I have setup "TZ=GMT" on the sourcetype setup for my IIS logs, set in the indexer under props.conf.&lt;/P&gt;

&lt;P&gt;I have multiple IIS servers using the same source type. For most of my servers, all is well and I see that Splunk is converting the timezone to my local timezone (Pacific) based on my settings. However, there are a few servers that I see Splunk is interpretting 2 different timezones, see below:&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;&lt;STRONG&gt;10/21/19&lt;BR /&gt;
7:35:55.000 AM&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;2019-10-21 07:35:55 10.1.24.88 GET /api/..snip.. - 80 - 10.1.24.81 - - 200 0 0 6&lt;BR /&gt;
host = V-WEB-PA-2-P **source = C:\inetpub\logs\logfiles\W3SVC22\u_ex191021.log&lt;/EM&gt;* sourcetype = ms:iis:default*&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;10/21/19&lt;BR /&gt;
7:35:54.000 AM&lt;/STRONG&gt;    &lt;/P&gt;

&lt;P&gt;*2019-10-21 14:35:54 10.1.24.88 POST /api/..snip.. - 80 - 10.1.24.88 - - 200 0 0 2&lt;/P&gt;

&lt;H2&gt;host = V-WEB-PA-2-P &lt;STRONG&gt;source = C:\inetpub\logs\logfiles\W3SVC22\u_ex191021.log&lt;/STRONG&gt; sourcetype = ms:iis:default*&lt;/H2&gt;

&lt;P&gt;Splunk is interpreting log entries with "7:35:xx" and 14:35:xx" as both IIS logs that have happened at 7:35:xx Localtime. The correct and expected interpretation is only log entries with "14:35:xx"  should be interpreted that way. &lt;/P&gt;

&lt;P&gt;You will notice that the same file is being used to make the two interpretations. &lt;/P&gt;

&lt;P&gt;Can anyone please point me in the direction of where I may have mis-configured Splunk, or why this is happening? &lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/2-Different-Timezones-being-interpreted-with-the-same-IIS-log/m-p/503210#M85731</guid>
      <dc:creator>derekho55</dc:creator>
      <dc:date>2020-09-30T02:34:58Z</dc:date>
    </item>
  </channel>
</rss>

