We have a sourcetype for /var/log/messages that is logged in the local server time on almost every host.
We have one host, however, which logs /var/log/messages (and some other files) in GMT. The system time on this host is set to the local timezone. This host is sending logs via the universal forwarder.
I understand that I need to probably need to modify props.conf on the Splunk host which is indexing the logs. My question is, how do I specify that I only want sourcetype foo from host bar (and ONLY host bar) to be in GMT?
Can I do something like this?
[source::/var/log/messages AND host::bar]