All Apps and Add-ons

Splunk App for Stream: Where do I set the timezone of the timestamp field for packets captured by streamfwd?

kwchang_splunk
Splunk Employee
Splunk Employee

Hi,

Where can I set the timezone of the timestamp field of the packets captured by streamfwd?

It is always captured as UTC.
My customer wants to change it to local timezone.

Thank you.

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Not sure I understand the problem: streamfwd always uses UTC since time is absolute, and UTC or any other timezone is just a different representation of the same point in time. Splunk displays time in search results using the user local timezone, which is configurable (http://docs.splunk.com/Documentation/Splunk/6.0/Data/Applytimezoneoffsetstotimestamps) , so it shouldn't matter what timestamp formatting was used on ingestion. Does it make sense?

0 Karma

kwchang_splunk
Splunk Employee
Splunk Employee

Thank you for your answer.
My gov customer complains because UTC timestamp is not intuitive. Do you have a plan for supporting it?

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

No, we don't have plans to support different timezone formatting for timestamps on ingestion. You can enter an enhancement request in JIRA though, and we'll review it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...