How can I see what timezone the forwarder is using in my v6 to v6 splunk setup?
I'm just curious to verify it's set properly, that's all. Seeing the timezone might help me find a machine with an incorrect timezone too.
Thanks,
Brian
http://docs.splunk.com/Documentation/Splunk/6.0.1/data/Applytimezoneoffsetstotimestamps
Hi BP9906,
you could use the date_zone
field which contains the time zone offset from GMT in minutes and do some reporting on it ... like
your search to get all universal forwarders | stats count by date_zone, host
hope this helps ...
cheers, MuS