All Apps and Add-ons
Highlighted

How to index the message trace report with local timestamp

Engager

I can use microsoft office 365 reporting add-on to collect message trace reports, however all the reports are default to UTC time. can we have some configuration in this add-on so that when it is consumed by splunk the timestamp can be converted to local time?

Thanks.

Highlighted

Re: How to index the message trace report with local timestamp

Path Finder

Try to add file props.conf with the following content (in etc/apps/TA-MSO365Reporting/local/):
[ms:o365:reporting:messagetrace]
TZ = Zulu

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.