Getting Data In

Is there a way to edit props or transforms to keep the UTC time but convert it to local CST time?

Log_wrangler
Builder

I have some logs rolling into splunk (via HF) in UTC time, and it is throwing off users' searching with CST (local time).

Is there a way to edit props or transforms to keep the UTC time but convert it to local CST time?

Or is that not an option?

Thank you

0 Karma
1 Solution

sudosplunk
Motivator

Hi Log_wrangler,

Yes, you can achieve this by using props.conf. Be sure to push this to both UF and HF.

[source::your_source]
TZ = US/Central
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...