I would like to update the date and timestamp for an event during indexing.
The data is in the following format:
The timestamp value is in GMT format and I need to convert it into PDT / PST. Splunk Server runs in PST/PDT.
Would just setting the TIME_FORMAT take care of it or do I need to set the Prefix too?
You need to set the prefix as well, since TIME_FORMAT will only look at the beginning of the line, by default:
TIME_PREFIX = <timestamp>
TIME_FORMAT = %Y-%m-%dT%T.%Q
TZ = UTC
Thank you Steve. This helped greatly.