All Apps and Add-ons

Splunk Add-on for ServiceNow: Why are event timestamps converted to UTC instead of CET?


I'm having an issue with the data pulled in by the Splunk Add-on for ServiceNow. Timestamps of events are converted to UTC instead of CET. I've tried to set up a props.conf for the add-on like this:

TIME_FORMAT=%y-%m-%d %h:%M:%S

But no luck. Time of the sys_updated_on is still 2 hours off.

Any ideas?


All, has anyone seen workarounds for this issues ? Servicenow does seem to record times in UTC and we need to see if there is easier alternative using configuration (apart from field level extractions and changes) for resolving this issue.

0 Karma


Any progress on this? I am facing the exact same problem on Splunk 6.5.2.


Where did you put that props.conf entry? It'll need to go wherever you are running the service now inputs from (ie: search head or heavy forwarder).

0 Karma


Hi Jeremiah

It's a one server setup. So I just have a Splunk enterprise server that connects to the servicenow api

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...