Hi.
With some network devices to the server Splunk receives syslog-events. Time on these devices is set to GMT. Events come to a time shift at 4:00. Identified these events as a separate sourcetype - sourcetype_VG.
Prescribed in props.conf:
[sourcetype::sourcetype_VG]
TZ = UTC
No changes over time is not happening.
I would be glad of any help!
Hello
To set a staza by sourcetype you only need to type the sourcetype name, like:
[sourcetype_VG]
regards
Tried - no change.