Hi all,
I'm new to this forum. Would be really happy if you could help me with this.
I am ingesting Bluecode ProxySG logs via syslog as recommended with the log format configuration provided by splunk.
$(date)T$(x-bluecoat-hour-utc):$(x-bluecoat-minute-utc):$(x-bluecoat-second-utc).000z $(s-computername) bluecoat - splunk_format
https://docs.splunk.com/Documentation/AddOns/released/BlueCoatProxySG/Setup
The event time of a proxySG event is always showed with UTC +2 which is causing Splunk to not recognize the time.
Can keep the format configuration and set the ProxySG to local time to avoid the UTC? Will this configuration still be working and simply not just showing +2?
Regards,
O.