I'm having an issue with the data pulled in by the Splunk Add-on for ServiceNow. Timestamps of events are converted to UTC instead of CET. I've tried to set up a props.conf for the add-on like this:
[snow:u_incident_task] SHOULD_LINEMERGE=false TIME_FORMAT=%y-%m-%d %h:%M:%S TZ=Europe/Amsterdam REPORT-sys=sys_id
But no luck. Time of the sys_updated_on is still 2 hours off.
All, has anyone seen workarounds for this issues ? Servicenow does seem to record times in UTC and we need to see if there is easier alternative using configuration (apart from field level extractions and changes) for resolving this issue.