Getting Data In

Is there a way to edit props or transforms to keep the UTC time but convert it to local CST time?

Log_wrangler
Builder

I have some logs rolling into splunk (via HF) in UTC time, and it is throwing off users' searching with CST (local time).

Is there a way to edit props or transforms to keep the UTC time but convert it to local CST time?

Or is that not an option?

Thank you

0 Karma
1 Solution

sudosplunk
Motivator

Hi Log_wrangler,

Yes, you can achieve this by using props.conf. Be sure to push this to both UF and HF.

[source::your_source]
TZ = US/Central
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...