With some network devices to the server Splunk receives syslog-events. Time on these devices is set to GMT. Events come to a time shift at 4:00. Identified these events as a separate sourcetype - sourcetype_VG.
Prescribed in props.conf:
TZ = UTC
No changes over time is not happening.
I would be glad of any help!
To set a staza by sourcetype you only need to type the sourcetype name, like:
Tried - no change.