Getting Data In

Defining time zone (TZ) value for Manual Host Extraction for syslog input

akshatj2
Path Finder

HI All,

I have created an inputs stanza for syslog input and created a manual host override using transforms. I tried to change the TZ value per host but it is not working. However, it works fine, if used per source type.
Kindly suggest how to fix

Inputs.conf

  [tcp://<port>]
    sourcetype = <custom_sourcetype>

Props.conf

 [host::ABC]
    TZ = UTC
    [host::DEF]
    TZ = Europe/London
0 Karma

itradeclayton
Path Finder

Did you ever figure this out? It's driving me crazy. I can't change all my "syslog" sourcetypes to the same timezone. I need to change by host or source etc.

0 Karma

akshatj2
Path Finder

Could you tell me where are you trying to define the TZ value

i would assume you have a heavy forwarder in place which is used to receive messages from syslog.

If yes you can try to set TZ value in your HF it should work. Also, make sure that splunk is taking time from the logs by setting appropriate Time Prefix and Time Format.

If still does not work can you give me more details so I can try to help you.

0 Karma

itradeclayton
Path Finder

I eventually figured it out... it just always seems to take some fiddling... the syntax for this doesn't always match what you can do in inputs.conf it seems. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...