Getting Data In

Defining time zone (TZ) value for Manual Host Extraction for syslog input

akshatj2
Path Finder

HI All,

I have created an inputs stanza for syslog input and created a manual host override using transforms. I tried to change the TZ value per host but it is not working. However, it works fine, if used per source type.
Kindly suggest how to fix

Inputs.conf

  [tcp://<port>]
    sourcetype = <custom_sourcetype>

Props.conf

 [host::ABC]
    TZ = UTC
    [host::DEF]
    TZ = Europe/London
0 Karma

itradeclayton
Path Finder

Did you ever figure this out? It's driving me crazy. I can't change all my "syslog" sourcetypes to the same timezone. I need to change by host or source etc.

0 Karma

akshatj2
Path Finder

Could you tell me where are you trying to define the TZ value

i would assume you have a heavy forwarder in place which is used to receive messages from syslog.

If yes you can try to set TZ value in your HF it should work. Also, make sure that splunk is taking time from the logs by setting appropriate Time Prefix and Time Format.

If still does not work can you give me more details so I can try to help you.

0 Karma

itradeclayton
Path Finder

I eventually figured it out... it just always seems to take some fiddling... the syntax for this doesn't always match what you can do in inputs.conf it seems. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...