<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to  adjust the time zone  for an logs coming into splunk ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306854#M165591</link>
    <description>&lt;P&gt;Hi garethatiag, I am  did not understand what I need to do from the above comment.  so please tell me what I need to add and where I need to add.&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 21:38:48 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2017-10-13T21:38:48Z</dc:date>
    <item>
      <title>How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306839#M165576</link>
      <description>&lt;P&gt;Hi All, Currently we are facing an issue time stamp for a firewall logs. We could see the logs are coming into splunk with a time difference of 3 hours. &lt;/P&gt;

&lt;P&gt;Exact Problem:&lt;BR /&gt;
 Example :  Current EDT time is 7:31 AM and logs are coming into splunk with a timestamp of &lt;BR /&gt;
4:30:54.000 AM, so need to adjust the time zone by 3 hours to match the current EDT time. &lt;/P&gt;

&lt;P&gt;inputs.conf detail :&lt;BR /&gt;
[monitor:///opt/syslogs/mguard/.../mguard.log*] &lt;BR /&gt;
index=fw&lt;BR /&gt;
sourcetype=mguard:network:log &lt;BR /&gt;
host_segment = 4 &lt;/P&gt;

&lt;P&gt;We have 5 heavy forwarder instance as intermediate forwarder and this firewall log is read from this 5 HF instance which is configured as syslogs server.  The splunk reads the logs from these 5 HF instance and then ingest the data into indexer. &lt;/P&gt;

&lt;P&gt;Kindly guide me how to adjust this time zone by 3 hours in splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 11:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306839#M165576</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T11:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306840#M165577</link>
      <description>&lt;P&gt;In the props.conf you can adjust the TZ= setting for your sourcetype, you will need to do this on the heavy forwarder.&lt;BR /&gt;
This is of course assuming the time is parsing as expected, if not consider configuring TIME_PREFIX and TIME_FORMAT in the props.conf file...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[firewall_sourcetype_goes_here]
TZ = GMT
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Where you put the appropriate timezone/sourcetype above...there is more documentation around &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps" target="_blank"&gt;specifying time zones here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306840#M165577</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-09-29T16:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306841#M165578</link>
      <description>&lt;P&gt;hi Garethatiag, thanks for your effort, Currently we are getting the data with time stamp in EDT but only things  time stamp has three hours behind the actual current EDT time.&lt;/P&gt;

&lt;P&gt;Event details :&lt;/P&gt;

&lt;P&gt;10/13/17&lt;BR /&gt;
6:49:37.000 AM&lt;BR /&gt;&lt;BR /&gt;
Oct 13 06:49:37 XXXX.XXXX.com 1,2017/10/13 06:49:37,007257000034869,TRAFFIC,start,0,2017/10/13 06:49:37,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-XXXX,,,ssl,vsys1,trust,XXXX,ethernet1/2,ethernet1/1,Splunk,2017/10/13 06:49:37,751336,1,51214,10194,0,0,0x104041,tcp,allow,664,421,185,6,2017/10/13 06:49:37,0,computer-and-internet-info,0,6991231,0x0,x.0.0.0-x.255.255.255,United States,0,4,2,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;BR /&gt;
host =  test01.XXXXs.com source =/opt/syslogs/mguard/test01.XXXXs.com/mgaurd.log sourcetype =   mguard:network:log &lt;BR /&gt;
10/13/17&lt;BR /&gt;
6:49:37.000 AM&lt;BR /&gt;&lt;BR /&gt;
Oct 13 06:49:37 test01.XXXXs.com 1,2017/10/13 06:49:37,007257000034869,TRAFFIC,s&lt;/P&gt;

&lt;P&gt;Current time at EDT is 9:53 AM and if we can see there is 3 hours difference between them. so which i need to adjust to make it to the exact EDT time.&lt;/P&gt;

&lt;P&gt;HF server time : Fri Oct 13 09:53:20 EDT 2017&lt;/P&gt;

&lt;P&gt;Can I had props.conf like this and will this fix the timestamp issue. &lt;/P&gt;

&lt;P&gt;[mguard:network:log]&lt;BR /&gt;
 TZ = EDT&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306841#M165578</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T13:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306842#M165579</link>
      <description>&lt;P&gt;Hi All, Can anyone guide me on this issue. &lt;BR /&gt;
thanks in advance. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 15:51:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306842#M165579</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T15:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306843#M165580</link>
      <description>&lt;P&gt;Hi garethatiag, I had tried to push the below stanza to the all the HF instance along with the inputs.conf file but still i am facing the issue. &lt;/P&gt;

&lt;P&gt;inputs.conf detail :&lt;BR /&gt;
[monitor:///opt/syslogs/mguard/.../mguard.log*] &lt;BR /&gt;
index=fw&lt;BR /&gt;
sourcetype=mguard:network:log &lt;BR /&gt;
host_segment = 4&lt;/P&gt;

&lt;P&gt;Props.conf: &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = EDT&lt;/P&gt;

&lt;P&gt;Latest Event detail after updating the above props.conf stanza : &lt;/P&gt;

&lt;P&gt;10/13/17&lt;BR /&gt;
10:35:57.000 AM &lt;BR /&gt;
Oct 13 10:35:57 test01.xxx.com 1,2017/10/13 10:35:57,007257000034869,TRAFFIC,start,0,2017/10/13 10:35:57,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-xxxx,,,ssl,vsys1,trust,xxxx,ethernet1/2,ethernet1/1,Splunk,2017/10/13 10:35:57,761997,1,51475,8089,0,0,0x104000,tcp,allow,416,350,66,4,2017/10/13 10:35:56,0,any,0,70021120,0x0,x.0.0.0-x.255.255.255,United States,0,3,1,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;BR /&gt;
eventtype = nix-all-logs    eventtype = pan     network host =  test01.xxx.com source = /opt/syslogs/mguard/test01.xxx.com/mguard.log sourcetype =  mguard:network:log tag =    network timeendpos =    16 timestartpos =   0&lt;/P&gt;

&lt;P&gt;Current EDT time is 1:40 PM and logs are coming into splunk with a timestamp of &lt;BR /&gt;
10:35:57.000 AM, so need to adjust the time zone by 3 hours to match the current EDT time.&lt;/P&gt;

&lt;P&gt;Kindly guide me how to adjust this time zone by 3 hours in splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 17:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306843#M165580</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T17:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306844#M165581</link>
      <description>&lt;P&gt;Hi All, Can anyone guide me on this, I need to adjust this time zone by 3 hours in splunk.&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 19:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306844#M165581</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T19:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306845#M165582</link>
      <description>&lt;P&gt;Hi All, is there any one to guide me in this ? I need to adjust the time zone by 3 hours in splunk. &lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 19:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306845#M165582</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T19:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306846#M165583</link>
      <description>&lt;P&gt;Hi garethatiag, could please guide me how to fix this issue. &lt;/P&gt;

&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 20:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306846#M165583</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T20:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306847#M165584</link>
      <description>&lt;P&gt;Ok so the logs are timestamped as 3 hours behind what you expect, this shouldn't be too hard to fix.&lt;/P&gt;

&lt;P&gt;Perhaps:&lt;BR /&gt;
Etc/GMT+8&lt;/P&gt;

&lt;P&gt;Or is it:&lt;/P&gt;

&lt;P&gt;Etc/GMT+2&lt;/P&gt;

&lt;P&gt;? As per this &lt;A href="https://en.wikipedia.org/wiki/List_of_tz_database_time_zones"&gt;article&lt;/A&gt; the sign is inverted, the above is actually -08:00 and -02:00 in terms of time, which is 3 hours different from your current -05:00 timezone.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 20:53:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306847#M165584</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-13T20:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306848#M165585</link>
      <description>&lt;P&gt;hi garethatiag,  thanks for working on this,  could please let me know how to include above mentioned details in props.conf&lt;/P&gt;

&lt;P&gt;Props.conf: &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = GMT+3  &lt;/P&gt;

&lt;P&gt;Below event detail are taken by keeping the time frame for last 24 hrs and current time in pennsylvania is 5:00 PM but index time is 3 hours behind the current time. So I need to fix this to match the current time. &lt;/P&gt;

&lt;P&gt;Event details:&lt;/P&gt;

&lt;P&gt;10/13/17&lt;BR /&gt;
2:00:15.000 PM&lt;BR /&gt;&lt;BR /&gt;
Oct 13 14:00:15 test01.xxx.com1,2017/10/13 14:00:14,007257000034869,TRAFFIC,end,0,2017/10/13 14:00:14,10.x.x.x,51.x.x.x.x,0.0.0.0,0.0.0.0,trust-test01,,,incomplete,vsys1,trust,test01,ethernet1/2,ethernet1/1,Splunk,2017/10/13 14:00:14,770183,1,57307,443,0,0,0x4064,tcp,allow,132,132,0,2,2017/10/13 14:00:06,3,any,0,70039854,0x0,10.0.0.0-10.255.255.255,United States,0,2,0,aged-out,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:10:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306848#M165585</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T21:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306849#M165586</link>
      <description>&lt;P&gt;Two things to confirm here, you are either pushing the props.conf via the deployment server to the heavy forwarder and it is triggering some kind of reload or restart.&lt;/P&gt;

&lt;P&gt;Or you have restarted the heavy forwarder after updating the below props.conf ?&lt;BR /&gt;
Finally, are you looking at newly indexed data?&lt;/P&gt;

&lt;P&gt;A props.conf change related to timestamps will work for &lt;EM&gt;newly&lt;/EM&gt; indexed data, the time of the already indexed events cannot be changed.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306849#M165586</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-13T21:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306850#M165587</link>
      <description>&lt;P&gt;hi garethatiag kindly guide me on this issue, it has been taking my time since morning.&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306850#M165587</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T21:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306851#M165588</link>
      <description>&lt;P&gt;If you see the above comment, can you confirm you did restart/reindexed some data ?&lt;/P&gt;

&lt;P&gt;When looking at the data that is an issue try adding this to the end:&lt;BR /&gt;
| eval indextime=strftime(_indextime, "%+")&lt;/P&gt;

&lt;P&gt;That will add an indextime to the fields available, the _time field will only be changed by props.conf for data indexed &lt;EM&gt;after&lt;/EM&gt; you updated the props.conf / restarted the heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:25:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306851#M165588</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-13T21:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306852#M165589</link>
      <description>&lt;P&gt;hi garethatiag, we have customized app and its pushed via deployer, in forwardmanagement we had mentioned enable the app /restart splunkd. so it should have been restarted when we execute splunk reload deploy-server.&lt;/P&gt;

&lt;P&gt;I have taken the recent data after pushing the props.conf via deployer to HF instances. &lt;/P&gt;

&lt;P&gt;Props.conf: &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = EDT&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306852#M165589</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T21:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306853#M165590</link>
      <description>&lt;P&gt;Try setting:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mgaurd:network:log]
TZ = Etc/GMT+8
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That will make the events appear to be 3 hours older than the EDT time of GMT-5 as per &lt;A href="https://en.wikipedia.org/wiki/List_of_tz_database_time_zones"&gt;this article&lt;/A&gt; the +8 is actually -8 in time zones..&lt;BR /&gt;
I &lt;EM&gt;think&lt;/EM&gt; that will add 3 hours into the incoming events which is what you would expect but you will need to test it, I don't have access to a test instance at the moment.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:31:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306853#M165590</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-13T21:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306854#M165591</link>
      <description>&lt;P&gt;Hi garethatiag, I am  did not understand what I need to do from the above comment.  so please tell me what I need to add and where I need to add.&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306854#M165591</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-13T21:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306855#M165592</link>
      <description>&lt;P&gt;This was the comment that will change the time of new incoming data, test something like this by re-ingesting some data and see what happens, this is just props.conf so replace the other TZ= setting with this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mgaurd:network:log]
TZ = Etc/GMT+8
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That will make the events appear to be 3 hours older than the EDT time of GMT-5 as per &lt;A href="https://en.wikipedia.org/wiki/List_of_tz_database_time_zones"&gt;this article&lt;/A&gt; the +8 is actually -8 in time zones..&lt;BR /&gt;
I &lt;EM&gt;think&lt;/EM&gt; that will add 3 hours into the incoming events which is what you would expect but you will need to test it, I don't have access to a test instance at the moment.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 21:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306855#M165592</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-13T21:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306856#M165593</link>
      <description>&lt;P&gt;Hi garethatiag, I had tried the above stanza in props.conf but it did not work. Kindly guide me how to adjust this time zone by 3 hours in splunk.&lt;/P&gt;

&lt;P&gt;thanks in advance &lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 12:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306856#M165593</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-16T12:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306857#M165594</link>
      <description>&lt;P&gt;Hi garethatiag, I had tried the below stanza in props.conf and it worked perfectly. Currently we could see log data are getting indexed as per the current time in EDT time zone.  Thanks for your much need effort on this issue. &lt;/P&gt;

&lt;P&gt;Props.conf &lt;BR /&gt;
[mgaurd:network:log]&lt;BR /&gt;
TZ = GMT&lt;/P&gt;

&lt;P&gt;Now I could see the index time is matching the current time of EDT.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 12:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306857#M165594</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-16T12:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to  adjust the time zone  for an logs coming into splunk ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306858#M165595</link>
      <description>&lt;P&gt;Hi Garethatiag, Hey the issue is not fixed, we are facing same time stamp issue for firewall logs.  Again the logs are coming into splunk with a time difference of 3 hours. Recently the firewall team has re-configured this device and the timezone on the device is now UTC . So I had updated the below stanza details in props.conf and after updating props.conf in the customized app , event data are not getting ingested into splunk.&lt;/P&gt;

&lt;P&gt;[mgaurd:network:log]&lt;BR /&gt;
TZ = UTC&lt;/P&gt;

&lt;P&gt;Exact Two Problem:&lt;/P&gt;

&lt;P&gt;1 )When the above the props.conf, is added into app, then the firewall data are not getting ingested into splunk.&lt;/P&gt;

&lt;P&gt;2) Similarly when the above props.conf is removed from the customized app, then the firewall data are getting indexed into splunk but with a time difference of 3 hours.&lt;/P&gt;

&lt;P&gt;Event details &lt;BR /&gt;
10/17/17&lt;BR /&gt;
4:21:56.000 AM &lt;BR /&gt;
Oct 17 04:21:56 test01.xxx.com 1,2017/10/17 04:21:55,007257000034869,TRAFFIC,start,0,2017/10/17 04:21:55,10.x.x.x,168.x.x.x,0.0.0.0,0.0.0.0,trust-xxxx,,,ssl,vsys1,trust,xxxx,ethernet1/2,ethernet1/1,Splunk,2017/10/17 04:21:55,229798,1,49472,10194,0,0,0x104041,tcp,allow,838,653,185,6,2017/10/17 04:21:55,0,computer-and-internet-info,0,70586295,0x0,10.x.x.x,10.x.x.x,United States,0,4,2,n/a,0,0,0,0,,test01,from-policy,,,0,,0,,N/A&lt;BR /&gt;
host = test01.xxx.com source = /opt/syslogs/mguard/test01.xxx.com/mguard.log sourcetype = mguard:network:log&lt;/P&gt;

&lt;P&gt;Current time in pennsylvania is 7:22 AM and if you can see the event data indexed time is 4:21 AM almost 3 hours difference its getting logged in.&lt;/P&gt;

&lt;P&gt;Kindly guide me on this to fix the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 11:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-adjust-the-time-zone-for-an-logs-coming-into-splunk/m-p/306858#M165595</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-10-17T11:35:10Z</dc:date>
    </item>
  </channel>
</rss>

