<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timezone issue in Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/689984#M235057</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Need your assistance for the configuration changes in Splunk. The requirement is to change the Timezone based on different “source” (not sourcetype).&lt;/P&gt;&lt;P&gt;We have different sources defined in our application. All of them are in their respective server timezone, except for the below 2 sources (these 2 are in EST timezone &amp;amp; our requirement is to change it into CET timezone)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source=/applications/testscan/*/testscn01/*
source=/applications/testscan/*/testcpdom/*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For rest of the other sources, I do not want make any change in the Timezone.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source=/applications/testscan/*/testscn02/*
source=/applications/testscan/*/testnycus/*
source=/applications/testscan/*/testnyus2/*
source=/applications/testscan/*/testshape/*
source=/applications/testscan/*/testshape2/*
source=/applications/testscan/*/testshape3/*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please note, we do not have any "props.conf" file available or configured in the server.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We are maintaining splunk configuration in only "inputs.conf" file. The present content of "inputs.conf" as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///applications/testscan/.../]
whitelist = (?:tools\/test\/log\/|TODAY\/LOGS\/)*\.(?:log|txt)$
index = testscan_prod
sourcetype = testscan
_TCP_ROUTING = in_prod

[monitor:///applications/testscan/*/*/tools/test_transfer/log]
index = testscan_prod
sourcetype = testscan
_TCP_ROUTING = in_prod

[monitor:///applications/testscan/*/*/tools/test_reports/log]
index = testscan_prod
sourcetype = testscan
_TCP_ROUTING = in_prod&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Please suggest what changes to be done so that Timezone can be managed based on the "source" information provided.&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 08 Jun 2024 18:33:16 GMT</pubDate>
    <dc:creator>shashankk</dc:creator>
    <dc:date>2024-06-08T18:33:16Z</dc:date>
    <item>
      <title>Timezone issue in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/689984#M235057</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Need your assistance for the configuration changes in Splunk. The requirement is to change the Timezone based on different “source” (not sourcetype).&lt;/P&gt;&lt;P&gt;We have different sources defined in our application. All of them are in their respective server timezone, except for the below 2 sources (these 2 are in EST timezone &amp;amp; our requirement is to change it into CET timezone)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source=/applications/testscan/*/testscn01/*
source=/applications/testscan/*/testcpdom/*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For rest of the other sources, I do not want make any change in the Timezone.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source=/applications/testscan/*/testscn02/*
source=/applications/testscan/*/testnycus/*
source=/applications/testscan/*/testnyus2/*
source=/applications/testscan/*/testshape/*
source=/applications/testscan/*/testshape2/*
source=/applications/testscan/*/testshape3/*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please note, we do not have any "props.conf" file available or configured in the server.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We are maintaining splunk configuration in only "inputs.conf" file. The present content of "inputs.conf" as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///applications/testscan/.../]
whitelist = (?:tools\/test\/log\/|TODAY\/LOGS\/)*\.(?:log|txt)$
index = testscan_prod
sourcetype = testscan
_TCP_ROUTING = in_prod

[monitor:///applications/testscan/*/*/tools/test_transfer/log]
index = testscan_prod
sourcetype = testscan
_TCP_ROUTING = in_prod

[monitor:///applications/testscan/*/*/tools/test_reports/log]
index = testscan_prod
sourcetype = testscan
_TCP_ROUTING = in_prod&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Please suggest what changes to be done so that Timezone can be managed based on the "source" information provided.&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2024 18:33:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/689984#M235057</guid>
      <dc:creator>shashankk</dc:creator>
      <dc:date>2024-06-08T18:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Timezone issue in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/690031#M235062</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Please note, we do not have any "props.conf" file available or configured in the server.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We are maintaining splunk configuration in only "inputs.conf" file.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258022"&gt;@shashankk&lt;/a&gt;&amp;nbsp;.. more details pls..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;is it a dev/test environment or prod..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;do you have Deployment server or not..&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;any reasons for not having a props.conf and only having inputs.onf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;that inputs.conf is on HF or indexer?... you use UF's or some applications send the logs to the monitored folders directly..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 16:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/690031#M235062</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-06-07T16:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Timezone issue in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/690034#M235064</link>
      <description>&lt;P&gt;Building on what &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt; said, it is strongly recommended that every sourcetype have a props.conf stanza.&amp;nbsp; Splunk can guess about how to interpret your data, but using explicit instructions via props.conf is more performant.&amp;nbsp; If you need to override default behavior, such as specifying a different time zone, props.conf is required.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 16:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timezone-issue-in-Splunk/m-p/690034#M235064</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-07T16:59:41Z</dc:date>
    </item>
  </channel>
</rss>

