Getting Data In

Skipping time conversion

MOHITJOSHI
Engager

I have events which has EST timestamp already and i don't want splunk to do any time conversion.

whats occurring right now is splunk is transforming this to EST again thinking its UTC time.

raw event time- 02/05/2020 02:08:49.074
splunk timestamp - 2/4/20 9:08:49.074 PM

i am looking to have no transformation applied and keep the raw event time as the timestamp
alt text

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Add TZ = EST to the appropriate props.conf stanza.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Add TZ = EST to the appropriate props.conf stanza.

---
If this reply helps you, Karma would be appreciated.
0 Karma

MOHITJOSHI
Engager

ah..i figured out...it needed a restart of splunk.

0 Karma

MOHITJOSHI
Engager

Tried that already but still the same.

[mysourcetype]
TZ = EST

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...