How to index the message trace report with local timestamp


I can use microsoft office 365 reporting add-on to collect message trace reports, however all the reports are default to UTC time. can we have some configuration in this add-on so that when it is consumed by splunk the timestamp can be converted to local time?


Path Finder

Try to add file props.conf with the following content (in etc/apps/TA-MS_O365_Reporting/local/):
TZ = Zulu