<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk displaying events with the correct timezone in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50451#M9622</link>
    <description>&lt;P&gt;Looks to be working now&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2012 16:15:40 GMT</pubDate>
    <dc:creator>Ant1D</dc:creator>
    <dc:date>2012-09-04T16:15:40Z</dc:date>
    <item>
      <title>Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50446#M9617</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have some data in an index where the events all begin with a UTC timestamp. My Splunk indexer server is in the UK and I would like the timestamps for these events to be interpreted as being in the Splunk indexer timezone (UK) instead of the UTC.&lt;/P&gt;

&lt;P&gt;How can I do this?&lt;/P&gt;

&lt;P&gt;At present, if a new event arrives at 11AM UK time, the timestamp will say 10AM which is the UTC time so it means that any searches that I do over the last 60 minutes or less will return no results which should not be the case.&lt;/P&gt;

&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 11:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50446#M9617</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T11:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50447#M9618</link>
      <description>&lt;P&gt;Hi Ant1D&lt;/P&gt;

&lt;P&gt;have you check the &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.3/Data/ApplyTimezoneOffsetstotimestamps"&gt;docs&lt;/A&gt; on how to set different timezones?&lt;/P&gt;

&lt;P&gt;cheers,&lt;/P&gt;

&lt;P&gt;MuS&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 12:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50447#M9618</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-09-04T12:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50448#M9619</link>
      <description>&lt;P&gt;Here is the link for TZ settings in the Splunk Docs&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.3/Data/ApplyTimezoneOffsetstotimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.3/Data/ApplyTimezoneOffsetstotimestamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 14:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50448#M9619</guid>
      <dc:creator>whitewool</dc:creator>
      <dc:date>2012-09-04T14:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50449#M9620</link>
      <description>&lt;P&gt;I tried using the TZ = value attribute before and it didn't work. I guess I can try this again&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 15:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50449#M9620</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T15:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50450#M9621</link>
      <description>&lt;P&gt;I tried using the TZ = value attribute before and it didn't work. I guess I can try this again&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 15:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50450#M9621</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T15:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50451#M9622</link>
      <description>&lt;P&gt;Looks to be working now&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 16:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50451#M9622</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T16:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50452#M9623</link>
      <description>&lt;P&gt;The solution is to make the following addition to your props.conf file:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[the_sourcetype_name]&lt;BR /&gt;
TZ = the_timezone_that_your_timestamps_are_in&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;For this question, you would need to add &lt;CODE&gt;TZ = UTC&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 16:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50452#M9623</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T16:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50453#M9624</link>
      <description>&lt;P&gt;thanks for the link&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 16:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50453#M9624</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T16:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk displaying events with the correct timezone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50454#M9625</link>
      <description>&lt;P&gt;thanks for the link&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 16:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-displaying-events-with-the-correct-timezone/m-p/50454#M9625</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2012-09-04T16:20:14Z</dc:date>
    </item>
  </channel>
</rss>

