Getting Data In

Is it possible to use sourcetype and host stanzas for the same event?


We have the varonis ta and its props has the following section -




However, each varonis server that sends us data has a different time zone and the data doesn't have the time zone as part of it. Therefore, can I have also?


TZ = <Tokyo Time Zone>


Will it work?

Labels (1)
0 Karma


Yes it will. The precedence order will be of the below. 

  • source
  • host
  • sourcetype

An upvote would be appreciated if the above comment is helpful.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!