Getting Data In

Is there a way to edit props or transforms to keep the UTC time but convert it to local CST time?

Log_wrangler
Builder

I have some logs rolling into splunk (via HF) in UTC time, and it is throwing off users' searching with CST (local time).

Is there a way to edit props or transforms to keep the UTC time but convert it to local CST time?

Or is that not an option?

Thank you

0 Karma
1 Solution

sudosplunk
Motivator

Hi Log_wrangler,

Yes, you can achieve this by using props.conf. Be sure to push this to both UF and HF.

[source::your_source]
TZ = US/Central
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...