I have events which has EST timestamp already and i don't want splunk to do any time conversion.
whats occurring right now is splunk is transforming this to EST again thinking its UTC time.
raw event time- 02/05/2020 02:08:49.074
splunk timestamp - 2/4/20 9:08:49.074 PM
i am looking to have no transformation applied and keep the raw event time as the timestamp
Add TZ = EST
to the appropriate props.conf stanza.
Add TZ = EST
to the appropriate props.conf stanza.
ah..i figured out...it needed a restart of splunk.
Tried that already but still the same.
[mysourcetype]
TZ = EST