If I index an event with
2015-05-20 19:10:01.132 HKT This is an event in Hong Kong Time Zone
The timezone will not be recognized. If instead the event is
2015-05-20 19:10:01.132 HongKong This is an event in Hong Kong Time Zone
The timezone will be recognized. However the HKT is commonly used across my devices. How do I get Splunk to recognize HKT?
This is a known issue which will be solved with Splunk 6.2.4
There is an easy workaround to have this working on the current release:
1. mkdir $SPLUNK_HOME/share/splunk/zoneinfo
2. ( Assuming the Indexer is a Linux box ) cp /usr/share/zoneinfo/Hongkong $SPLUNK_HOME/share/splunk/zoneinfo/HKT
3. Restart Splunk.
And it will recognize the HKT timezone correctly.