All Apps and Add-ons

How to index the message trace report with local timestamp

dwangfeng
Engager

I can use microsoft office 365 reporting add-on to collect message trace reports, however all the reports are default to UTC time. can we have some configuration in this add-on so that when it is consumed by splunk the timestamp can be converted to local time?

Thanks.

wstarowicz
Path Finder

Try to add file props.conf with the following content (in etc/apps/TA-MS_O365_Reporting/local/):
[ms:o365:reporting:messagetrace]
TZ = Zulu

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...