<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk timestamp offset GMT in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529184#M89169</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You should try time format as "%y-%j-%H:%M:%S" and probably the correct time zone from inputs.conf if it isn't &amp;nbsp;in time string.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2020 17:35:04 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-11-12T17:35:04Z</dc:date>
    <item>
      <title>Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529043#M89155</link>
      <description>&lt;P&gt;Good evening.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a ASCII event message that looks like the following: The timestamp is in GMT time.&amp;nbsp; When Splunk coverts the timestamp the result is off by 5 hours. For this event message, the resulting timestamp is "11/11/20&lt;BR /&gt;5:46:39.969 PM" but should really be "11/11/20 12:46:39.969 PM". I have the servers local time zone set to "UTC -5 Eastern Time".&amp;nbsp; I already created a "props.conf" file and placed the following "TZ=Etc/GMT0", but it did not change the Splunk time stamp.&amp;nbsp;&lt;/P&gt;&lt;P&gt;INFO Stol 20-314-17:46:39.969: !!!!!!!!!INST Telemetry Started !!!!!!&lt;/P&gt;&lt;P&gt;Thank for your assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 21:15:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529043#M89155</guid>
      <dc:creator>SFOTC</dc:creator>
      <dc:date>2020-11-11T21:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529045#M89156</link>
      <description>&lt;P&gt;Timestamps as assumed to be in the same time zone as the Splunk server unless otherwise specified.&amp;nbsp; You have a TZ specified, but it's not working so we'll presume the setting is incorrect.&amp;nbsp; Begin by changing the TZ setting to "UTC" or "GMT".&amp;nbsp; Also, the props.conf file must be on the forwarder or indexer that first touches the event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that doesn't fix the problem then please share the complete props.conf stanza for event's souretype.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2020 21:38:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529045#M89156</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-11T21:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529065#M89158</link>
      <description>&lt;P&gt;Ok, thank I will give that a try. What directory are the "indexers" placed?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 02:33:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529065#M89158</guid>
      <dc:creator>SFOTC</dc:creator>
      <dc:date>2020-11-12T02:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529071#M89160</link>
      <description>From where you are collecting those files (same TZ than splunk indexers are or from an UF which TZ is UTC-5)? As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; said splunk indexers use GMT as internal time when they are storing events. But this information comes from event or from UF if events' have any timezone information. So if you are using UF and those are in TZ=UTC-5 then you must put that information to your inputs.conf on UF.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 12 Nov 2020 05:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529071#M89160</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-12T05:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529161#M89167</link>
      <description>&lt;P&gt;Thanks, we are a little closer to what we need, but I'm not sure if Splunk can do this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our event times are in: YY-DOY-HH:MM:SS (example: 20-316-23:16:36.36)&lt;/P&gt;&lt;P&gt;&amp;nbsp;The above example relates to a date of: 11/11/20 7:16.36pm (a time of 00:00:00 represents 8:00PM and a rollover of the next day).&amp;nbsp; Can Splunk handle a format like this?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 15:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529161#M89167</guid>
      <dc:creator>SFOTC</dc:creator>
      <dc:date>2020-11-12T15:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529184#M89169</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You should try time format as "%y-%j-%H:%M:%S" and probably the correct time zone from inputs.conf if it isn't &amp;nbsp;in time string.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 17:35:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529184#M89169</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-12T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timestamp offset GMT</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529197#M89171</link>
      <description>&lt;P&gt;Can you provide exact props and exact sample event?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 18:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timestamp-offset-GMT/m-p/529197#M89171</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2020-11-12T18:35:03Z</dc:date>
    </item>
  </channel>
</rss>

