How can I see what timezone the forwarder is using in my v6 to v6 splunk setup?
I'm just curious to verify it's set properly, that's all. Seeing the timezone might help me find a machine with an incorrect timezone too.
you could use the date_zone field which contains the time zone offset from GMT in minutes and do some reporting on it ... like
your search to get all universal forwarders | stats count by date_zone, host
hope this helps ...