Getting Data In

Can you help me get data from different time zones into CST time?

snigdhasaxena
Communicator

I have Splunk forwarders using time zone CST while the servers from where forwarders are picking up the data are in EST and GMT time zones.

What should be done to get all the data in CST time zone as used by the Splunk forwarder?

0 Karma
1 Solution

damann
Communicator

When all your forwarded data provide a valid timestamp with additional information of the timezone everything is fine. Splunk recognizes the timezone automatically for you and will adjust the timestamp while indexing.

Another way to make sure your events get indexed properly you should take a look in the props.conf:
https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

There you can specify the correct TZ for a set of servers by using stanzas as you can see in the examples.

View solution in original post

0 Karma

damann
Communicator

When all your forwarded data provide a valid timestamp with additional information of the timezone everything is fine. Splunk recognizes the timezone automatically for you and will adjust the timestamp while indexing.

Another way to make sure your events get indexed properly you should take a look in the props.conf:
https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

There you can specify the correct TZ for a set of servers by using stanzas as you can see in the examples.

0 Karma

dkeck
Influencer

Hi,

I don´t get why you wan´t to change the TZ from EST to CST on the same source, but..

you can set this in props.conf for host or source

https://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

valid TZ are listed here : https://en.wikipedia.org/wiki/List_of_tz_database_time_zones

Set this on your Indexer or Heavy Forwarder

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...