All Apps and Add-ons

How to index the message trace report with local timestamp

Engager

I can use microsoft office 365 reporting add-on to collect message trace reports, however all the reports are default to UTC time. can we have some configuration in this add-on so that when it is consumed by splunk the timestamp can be converted to local time?

Thanks.

Path Finder

Try to add file props.conf with the following content (in etc/apps/TA-MS_O365_Reporting/local/):
[ms:o365:reporting:messagetrace]
TZ = Zulu

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!