Hi,
Where can I set the timezone of the timestamp field of the packets captured by streamfwd?
It is always captured as UTC.
My customer wants to change it to local timezone.
Thank you.
hi kwchang,
Not sure I understand the problem: streamfwd always uses UTC since time is absolute, and UTC or any other timezone is just a different representation of the same point in time. Splunk displays time in search results using the user local timezone, which is configurable (http://docs.splunk.com/Documentation/Splunk/6.0/Data/Applytimezoneoffsetstotimestamps) , so it shouldn't matter what timestamp formatting was used on ingestion. Does it make sense?
Thank you for your answer.
My gov customer complains because UTC timestamp is not intuitive. Do you have a plan for supporting it?
No, we don't have plans to support different timezone formatting for timestamps on ingestion. You can enter an enhancement request in JIRA though, and we'll review it.