Getting Data In

Can you help me change the timezone offset for events that appear to be from the same host?

shariefc
New Member

How do I change the timezone offset for events that appear to be from the same host (but the real host and timezone is contained in the event)?

RAW EVENTS:

Event 1:
host=HOSTA
real_event_host=HOSTX
real_event_time=2018-09-25T06:39:03:142-06:00

Event 2:
host=HOSTA
real_event_host=HOSTY
real_event_time=2018-09-25T08:40:03:142-04:00

Here is how the above events get loaded:

Event 1:
_time=25/09/2018 06:39:03.000 (What I want is for this to now switch to the timezone of the indexer -400 i.e. 25/09/2018 08:39:03.142)
host=HOSTA
real_event_host=HOSTX
real_event_time=2018-09-25T06:39:03:142-06:00

Event 2:
_time=25/09/2018 08:40:03.321 (For this one the timezone is the same so the times should be the same)
host=HOSTA
real_event_host=HOSTY
real_event_time=2018-09-25T08:40:03:321-04:00

**How do I either use the real_event_time as the _time and convert it to the indexer's timezone OR at the very least make the _time reflect the timezone of the event?

HOSTX is in -600 timezone offset
HOSTY is in -400 timezone offset
Both events appear to come from HOSTA which is in -400 timezone offset because HOSTA is a log aggregator**

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...