Getting Data In

Is it possible to use sourcetype and host stanzas for the same event?


We have the varonis ta and its props has the following section -




However, each varonis server that sends us data has a different time zone and the data doesn't have the time zone as part of it. Therefore, can I have also?


TZ = <Tokyo Time Zone>


Will it work?

Yes it will. The precedence order will be of the below. 

  • source
  • host
  • sourcetype

