Getting Data In

Hong Kong Timezone HKT not being recognised ?

mzorzi
Splunk Employee
Splunk Employee

If I index an event with

2015-05-20 19:10:01.132 HKT This is an event  in Hong Kong Time Zone

The timezone will not be recognized. If instead the event is

2015-05-20 19:10:01.132 HongKong This is an event  in Hong Kong Time Zone

The timezone will be recognized. However the HKT is commonly used across my devices. How do I get Splunk to recognize HKT?

Tags (1)
0 Karma

mzorzi
Splunk Employee
Splunk Employee

This is a known issue which will be solved with Splunk 6.2.4

There is an easy workaround to have this working on the current release:

1. mkdir $SPLUNK_HOME/share/splunk/zoneinfo

2. ( Assuming the Indexer is a Linux box )  cp /usr/share/zoneinfo/Hongkong $SPLUNK_HOME/share/splunk/zoneinfo/HKT

3. Restart Splunk.

And it will recognize the HKT timezone correctly.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...