We are collecting logs from Infoblox and forwarding from the product into Splunk which is working as expected, however the timezone Splunk is indexing appears to be in GMT/UTC when the timestamps are actually in EST (when I run a search _time is 4 hours behind). I've gone through the documentation which references setting TZ in props.conf, but this has been unsuccessful so far. Also, Infoblox sends this data over a s2s tcp connection since Splunk is built in which acts as a Universal Forwarder.
Is it possible to set a TZ setting on the Infoblox side before sending logs over the Splunk or am I just missing something in my current configuration to get this to work?
For context, the infoblox DNS events do not have a timezone in the raw event and we are collecting the events in this fashion:
Infoblox (UF) -> HF -> IN
This is also my props.conf settings which are on the HF and IN:
[source::/infoblox/logs*]
TZ = US/Eastern
[host::servername*]
TZ = US/Eastern