All Apps and Add-ons

Splunk Add-on for ServiceNow: Why are event timestamps converted to UTC instead of CET?

florisvanhelvoo
Engager

I'm having an issue with the data pulled in by the Splunk Add-on for ServiceNow. Timestamps of events are converted to UTC instead of CET. I've tried to set up a props.conf for the add-on like this:

[snow:u_incident_task]
SHOULD_LINEMERGE=false
TIME_FORMAT=%y-%m-%d %h:%M:%S
TZ=Europe/Amsterdam
REPORT-sys=sys_id

But no luck. Time of the sys_updated_on is still 2 hours off.

Any ideas?

splunk4now
Explorer

All, has anyone seen workarounds for this issues ? Servicenow does seem to record times in UTC and we need to see if there is easier alternative using configuration (apart from field level extractions and changes) for resolving this issue.

0 Karma

niek33
Engager

Any progress on this? I am facing the exact same problem on Splunk 6.5.2.

Jeremiah
Motivator

Where did you put that props.conf entry? It'll need to go wherever you are running the service now inputs from (ie: search head or heavy forwarder).

0 Karma

florisvanhelvoo
Engager

Hi Jeremiah

It's a one server setup. So I just have a Splunk enterprise server that connects to the servicenow api

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...