<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set the time zone/alias for syslog data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551860#M91589</link>
    <description>&lt;P&gt;Have the syslog server put each source server's data into a different file.&amp;nbsp; The Universal Forwarder should monitor each file.&amp;nbsp; The inputs.conf file for the UF will have the appropriate TZ setting for each monitored file.&lt;/P&gt;</description>
    <pubDate>Mon, 17 May 2021 11:57:18 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-05-17T11:57:18Z</dc:date>
    <item>
      <title>How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551858#M91587</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;So, the scenario is that we have a central syslog server which receives syslog messages from different servers in the organization.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the syslog data is received on the syslog server, there is a universal forwarder agent on the syslog server that forwards it to Splunk. The issue is that some servers are using UTC time zone and therefore the syslog data from those servers contains UTC Timestamp.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to change how the forwarder interprets the syslog data file received from those servers? I've tried editing TZ=UTC and TZ-ALIAS=UTC in props.conf with the source stanza specifying the path for those specific log files that have UTC Timestamp in events. However in Splunk I still see those events with the UTC Time Stamp.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an issue due to which we can't properly search. Any advice would be much appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 11:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551858#M91587</guid>
      <dc:creator>AhmadKhattak20</dc:creator>
      <dc:date>2021-05-17T11:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551859#M91588</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can use the source:: and host:: stanzas within props.conf in order to edit the time zone for specific filepaths or host names. I normally use the source as it is unique to this particular type of data (Syslog) as opposed to the host. For instance:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::/var/log/syslog/firewall/myserverfilename*.log]
TZ=Europe/Madrid&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://en.wikipedia.org/wiki/List_of_tz_database_time_zones" target="_blank"&gt;https://en.wikipedia.org/wiki/List_of_tz_database_time_zones&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 11:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551859#M91588</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2021-05-17T11:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551860#M91589</link>
      <description>&lt;P&gt;Have the syslog server put each source server's data into a different file.&amp;nbsp; The Universal Forwarder should monitor each file.&amp;nbsp; The inputs.conf file for the UF will have the appropriate TZ setting for each monitored file.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 11:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551860#M91589</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-17T11:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551968#M91608</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, yes there is a different directory and file maintained. Although I've not used the inputs.conf to set the TZ property rather I've used the props.conf to set the TZ property.&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/113132"&gt;@javiergn&lt;/a&gt;, Yes, I've used this source stanza in the props.conf file however the events from the file still show up with UTC Timestamp.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 06:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551968#M91608</guid>
      <dc:creator>AhmadKhattak20</dc:creator>
      <dc:date>2021-05-18T06:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551977#M91609</link>
      <description>&lt;P&gt;Can you send a screenshot of the event's raw and _time?&lt;/P&gt;&lt;P&gt;Simple run&amp;nbsp; your search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo sourcetype=bar source=yoursyslogsource
| head 1
| table _time, _raw&lt;/LI-CODE&gt;&lt;P&gt;And also confirm what your user timezone is within the interface:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-05-18 at 09.20.19.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14196i37CFA4E5CE50A010/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-05-18 at 09.20.19.png" alt="Screenshot 2021-05-18 at 09.20.19.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 07:21:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/551977#M91609</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2021-05-18T07:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552045#M91619</link>
      <description>&lt;P&gt;You're right, the TZ property is set in props.conf, but it should be done on the UF.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 12:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552045#M91619</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-18T12:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552127#M91626</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/113132"&gt;@javiergn&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I ran the command that you gave me,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=syslog source=sourcename
| head 1
| _raw, _time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The result that I got was the following, (only showing the timestamps result)&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;_raw&lt;/TD&gt;&lt;TD width="50%"&gt;_time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;May 19 04:30:01&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;2021-05-19 04:30:01&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that Splunk is still extracting the time stamp from the event data itself and not converting the UTC time stamp to the one being used in Splunk Preferences.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The time zone preference set in Splunk User Preferences is below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="s1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14214iF136AA341D203604/image-size/medium?v=v2&amp;amp;px=400" role="button" title="s1.PNG" alt="s1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference what I've done in props.conf on the UF running on the Syslog Server is following,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::/path/*.log]
TZ=UTC
TZ_ALIAS=UTC&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 04:48:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552127#M91626</guid>
      <dc:creator>AhmadKhattak20</dc:creator>
      <dc:date>2021-05-19T04:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552153#M91629</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231072"&gt;@AhmadKhattak20&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Couple of things:&lt;/P&gt;&lt;P&gt;- You don't need the TZ_ALIAS. TZ = UTC is perfectly valid&lt;/P&gt;&lt;P&gt;- Where is this props.conf located within your Splunk installation directory?&lt;/P&gt;&lt;P&gt;- Can you also paste the value of your source so that we can validate the stanza? Use the following query&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=syslog source=sourcename
| head 1
| table _raw, _time, source&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 19 May 2021 08:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552153#M91629</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2021-05-19T08:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552159#M91630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/113132"&gt;@javiergn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I've removed the TZ_ALIAS from the props.conf.&lt;/P&gt;&lt;P&gt;I'm pushing the app from the deployment server onto the Syslog Server where a Splunk UF is installed.&lt;/P&gt;&lt;P&gt;On the Syslog Server, this is located under /opt/splunk/etc/apps/custom-app-folder/local/props.conf&lt;/P&gt;&lt;P&gt;I ran the query that you mentioned and the results are following,&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;_raw&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;_time&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;source&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;May 19 09:10:01 ….&lt;/TD&gt;&lt;TD&gt;2021-05-19 09:10:01&lt;/TD&gt;&lt;TD&gt;/var/splunk/path/ipaddress/2021-05-19-servername.log&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;I verified that the source that was showing up in the query results is the same that I'm using in the props.conf stanza for source, (this props.conf is pushed on the syslog server - it is not present in any indexers/search head)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::/var/splunk/path/ipaddress/*.log]
TZ = UTC&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 09:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552159#M91630</guid>
      <dc:creator>AhmadKhattak20</dc:creator>
      <dc:date>2021-05-19T09:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552166#M91632</link>
      <description>&lt;P&gt;OK, I think I know what the problem is thanks to your answer.&lt;/P&gt;&lt;P&gt;Your props.conf needs to go to your indexer (or Intermediate/Heavy Forwarder if there is any before reaching the Indexer). That's because you are using a Universal Forwarder and the TZ setting in props.conf is applied at parsing time:&lt;/P&gt;&lt;P&gt;&lt;A href="https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F" target="_blank"&gt;https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 09:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552166#M91632</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2021-05-19T09:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552192#M91635</link>
      <description>&lt;P&gt;Thank you, I pushed the props.conf with the below stanza on indexers and now I'm getting expected results.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::/var/splunk/path/ipaddress/*.log]
TZ = UTC&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 19 May 2021 11:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552192#M91635</guid>
      <dc:creator>AhmadKhattak20</dc:creator>
      <dc:date>2021-05-19T11:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to set the time zone/alias for syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552197#M91636</link>
      <description>&lt;P&gt;Great. Glad it worked.&lt;/P&gt;&lt;P&gt;Please don't forget to upvote the answers if you are happy with them.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 12:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-the-time-zone-alias-for-syslog-data/m-p/552197#M91636</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2021-05-19T12:13:48Z</dc:date>
    </item>
  </channel>
</rss>

