<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is _time indicating UTC when the event happened in EST. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575695#M200592</link>
    <description>&lt;P&gt;_time:&amp;nbsp;2021-11-19T11:34:02.000+0000&lt;/P&gt;&lt;P&gt;date_hour: 11&lt;/P&gt;&lt;P&gt;date_mday: 19&lt;/P&gt;&lt;P&gt;date_wday:&amp;nbsp;friday&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;date_year:&amp;nbsp;2021&lt;/P&gt;&lt;P&gt;date_zone:&amp;nbsp;-300&lt;/P&gt;&lt;P&gt;raw log snippet&lt;/P&gt;&lt;P&gt;[19/Nov/2021:11:34:02 -0500]&lt;/P&gt;&lt;P&gt;2021-11-19T11:34:02.000+0000 indicates UTC.&lt;/P&gt;&lt;P&gt;Does this indicate timezone?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Nov 2021 17:27:10 GMT</pubDate>
    <dc:creator>djreschke</dc:creator>
    <dc:date>2021-11-19T17:27:10Z</dc:date>
    <item>
      <title>Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575695#M200592</link>
      <description>&lt;P&gt;_time:&amp;nbsp;2021-11-19T11:34:02.000+0000&lt;/P&gt;&lt;P&gt;date_hour: 11&lt;/P&gt;&lt;P&gt;date_mday: 19&lt;/P&gt;&lt;P&gt;date_wday:&amp;nbsp;friday&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;date_year:&amp;nbsp;2021&lt;/P&gt;&lt;P&gt;date_zone:&amp;nbsp;-300&lt;/P&gt;&lt;P&gt;raw log snippet&lt;/P&gt;&lt;P&gt;[19/Nov/2021:11:34:02 -0500]&lt;/P&gt;&lt;P&gt;2021-11-19T11:34:02.000+0000 indicates UTC.&lt;/P&gt;&lt;P&gt;Does this indicate timezone?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 17:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575695#M200592</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-19T17:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575696#M200593</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/159258"&gt;@djreschke&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is based on the default timezone of the Splunk server.&lt;/P&gt;&lt;P&gt;The time zone can be changed based on the steps in the link below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;&lt;SPAN class=""&gt;Set your time zone&lt;/SPAN&gt;&lt;/H2&gt;&lt;P&gt;Choose the time zone in which you view events, anomalies, and threats.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;DIV class=""&gt;Select your username from the menu.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Profile&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Preferences&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;Select a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Time Zone&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of UTC or Local. The local time zone is detected based on your web browser settings.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to save.&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;Reference Link:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/UBA/5.0.5/User/Profile" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/UBA/5.0.5/User/Profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 17:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575696#M200593</guid>
      <dc:creator>vhharanpositka</dc:creator>
      <dc:date>2021-11-19T17:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575697#M200594</link>
      <description>&lt;P&gt;My timezone is in EST, so I would imagine the it would show something like -500?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 17:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575697#M200594</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-19T17:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575698#M200595</link>
      <description>&lt;P&gt;Yes, it is right&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 17:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575698#M200595</guid>
      <dc:creator>vhharanpositka</dc:creator>
      <dc:date>2021-11-19T17:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575701#M200596</link>
      <description>&lt;P&gt;Can you please clarify some more?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its right that is showing&amp;nbsp;2021-11-19T11:34:02.000+0000&lt;/P&gt;&lt;P&gt;Or is this wrong from based of my timezone.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 17:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575701#M200596</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-19T17:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575710#M200599</link>
      <description>&lt;P&gt;So when I export the log the it what it shows as _time, but i am seeing the correct _time in the field on the Search head.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a know thing that it drops the timezone when you export a log.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 18:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575710#M200599</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-19T18:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575714#M200602</link>
      <description>&lt;P&gt;There are various things that are happening here.&lt;/P&gt;&lt;P&gt;Firstly, the date_* fields - quoting from the docs (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Aboutdefaultfields" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Aboutdefaultfields&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;"Only events that have timestamp information in them as generated by their respective systems will have date_* fields. If an event has a date_* field, it represents the value of time/date directly from the event itself. If you have specified any timezone conversions or changed the value of the time/date at indexing or input time (for example, by setting the timestamp to be the time at index or input time), these fields will not represent that."&lt;/P&gt;&lt;P&gt;So don't rely too much on the date_* fields because they don't have to match (as you can see) the final parsed _time value.&lt;/P&gt;&lt;P&gt;Secondly, if you don't have your date format specified, splunk tries to find the date on its own but doesn't always do it properly (especially if the date is expressed somewhat exoticaly). Also, finding timestamp is one of the "heaviest" part of ingestion pipeline. So it's best to specify explicitly where the timestamp is within the event by means of TIME_PREFIX in props.conf and what is the timestamp format with TIME_FORMAT. If there is no timezone within the event itself you can also set TZ for a given sourcetype.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 18:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575714#M200602</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-19T18:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575716#M200604</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the time information is being parsed correctly, it is simply not so simply different on the _time field from the Web UI to the exported csv.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Web UI _time is showing:&amp;nbsp;2021-11-19T11:34:02.000-05:00&lt;/P&gt;&lt;P&gt;CSV Export _time is showing:&amp;nbsp;2021-11-19T11:34:02.000+0000&lt;/P&gt;&lt;P&gt;I never noticed the difference before today but for users that don't log into Splunk, they are assuming that the CSV _time is in UTC, so they are converting this to EST which puts this event at 630 in the morning, which is not correct.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 18:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575716#M200604</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-19T18:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575728#M200608</link>
      <description>&lt;P&gt;That's interesting, because indeed splunk does make something strange with _time export on CSV... when it's formated by default.&lt;/P&gt;&lt;P&gt;If I did simply&lt;/P&gt;&lt;PRE&gt;| makeresults&lt;/PRE&gt;&lt;P&gt;I'd get my results as&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PickleRick_0-1637351403712.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16941i83E87B436974DFD2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PickleRick_0-1637351403712.png" alt="PickleRick_0-1637351403712.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I exported the job to csv, I'd get&lt;/P&gt;&lt;PRE&gt;"_time"&lt;BR /&gt;"2021-11-19T20:49:41.000+0200"&lt;/PRE&gt;&lt;P&gt;But if I started fooling around with fieldformat I started getting weird results:&lt;/P&gt;&lt;PRE&gt;| makeresults &lt;BR /&gt;| eval t=_time&lt;BR /&gt;| fieldformat t=strftime(t,"%Y-%m-%d %H:%M:%S.%l %z")&lt;/PRE&gt;&lt;P&gt;As you can see, both fields, t and _time should have the same value. And in the WebUI it does indeed seem so:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PickleRick_1-1637351630205.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16942i58659BCEEBF84B38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PickleRick_1-1637351630205.png" alt="PickleRick_1-1637351630205.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the CSV export shows...&lt;/P&gt;&lt;PRE&gt;"_time",t&lt;BR /&gt;"2021-11-19T20:52:30.000+0200","2021-11-19 20:52:30.000 +0100"&lt;/PRE&gt;&lt;P&gt;So if we render the _time without the timezone information, CSV export produces the default timezone on its own anyway.&lt;/P&gt;&lt;P&gt;But if we render the _time with a proper timezone including format...&lt;/P&gt;&lt;PRE&gt;| makeresults &lt;BR /&gt;| eval t=_time&lt;BR /&gt;| fieldformat t=strftime(t,"%Y-%m-%d %H:%M:%S.%l %z")&lt;BR /&gt;| fieldformat _time=strftime(_time,"%Y-%m-%d %H:%M:%S.%l %z")&lt;/PRE&gt;&lt;P&gt;Again - t and _time are equal but this time also string representations are explicitly created with the same format, including timezone information.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PickleRick_2-1637351840075.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16943iF82E3236EAB4E7C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PickleRick_2-1637351840075.png" alt="PickleRick_2-1637351840075.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And now the CSV includes proper TZ information in both fields.&lt;/P&gt;&lt;PRE&gt;"_time",t&lt;BR /&gt;"2021-11-19 20:55:40.000 +0100","2021-11-19 20:55:40.000 +0100"&lt;/PRE&gt;&lt;P&gt;So it seems it's not the webUI that is at fault but there's something "wrong" with CSV export.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 19:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575728#M200608</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-19T19:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575729#M200609</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Agreed, the UI is correct, I can't post screenshots. I have open a support ticket with Splunk. Thank you for validating that there is a difference. I'll keep this post updated as I here back from Support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 20:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575729#M200609</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-19T20:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575868#M200679</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of Splunk are you running? I am running 8.1.1.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 13:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575868#M200679</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-11-22T13:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why is _time indicating UTC when the event happened in EST.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575921#M200704</link>
      <description>&lt;P&gt;Version:8.2.2.1&lt;/P&gt;&lt;P&gt;Build:ae6821b7c64b&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 19:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-time-indicating-UTC-when-the-event-happened-in-EST/m-p/575921#M200704</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-22T19:06:08Z</dc:date>
    </item>
  </channel>
</rss>

