Getting Data In
Highlighted

How to ignore timezone offset in timestamp?

Explorer

Hi there,

I have an application that is incorrectly reporting the current timezone is GMT -0500 with timestamps of the following form:

[29/Oct/2010:15:59:50 -0500]

(Currently we're on EDT which is -0400)

Is there a way i can accept the timestamp but ignore the offset? Currently all events are marked an hour in the future?

Thanks!

Tags (2)
0 Karma
Highlighted

Re: How to ignore timezone offset in timestamp?

Motivator

You can set an explicit time format in props.conf and leave the timezone offset out.

Take a look at:
     http://www.splunk.com/base/Documentation/latest/Admin/Configuretimestamprecognition

and look specifically at the TIME_FORMAT option.

View solution in original post

0 Karma
Highlighted

Re: How to ignore timezone offset in timestamp?

Explorer

Awesome. Thank you!

0 Karma
Highlighted

Re: How to ignore timezone offset in timestamp?

Path Finder
0 Karma