Getting Data In

Get source machine timezone in events

Vikas_Sharma
Explorer

Is there a way (if possible) to stamp the time zone of the machine running universal forwarder in the events (Windows eventlogs)? Both our indexers and UFs are on V6 and we get the source machine timestamp in Splunk. We are interested in getting the source machine timezone which can be helpful if we plan to forward the data to third party apps.

0 Karma

woodcock
Esteemed Legend

Splunk supplies you with what it interpreted the TZ to be for each event in the date_zone field. If this value is local, then the TZ of the indexing server (in the splunk_server field) was used.

0 Karma

Vikas_Sharma
Explorer

Thank you for the response.

The date_zone field is empty for the events. How can I set it up? Is it by using TZ in local/props.conf on the indexer, I tried it but it never worked (tried with [source::*] and [] as well).

[host::]
TZ=US/Eastern

0 Karma

woodcock
Esteemed Legend

This means that they came in from a modular input and it was probably timestamped with the the time that it was indexed or it was a WinEventLog:* and I don't know what those timestamps do.

0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...