You need to make sure to specify what the timezone of the data is, using the TZ
setting in props.conf or setting the TIME_FORMAT if the timezone is explicitly in the data. Splunk will always convert the timestamp internally to UTC/GMT, with the assumption that unspecified timezone data has the timezone of the indexer, and the display will always be formatted to the timezone of the search head.
You need to make sure to specify what the timezone of the data is, using the TZ
setting in props.conf or setting the TIME_FORMAT if the timezone is explicitly in the data. Splunk will always convert the timestamp internally to UTC/GMT, with the assumption that unspecified timezone data has the timezone of the indexer, and the display will always be formatted to the timezone of the search head.