Getting Data In

Splunk displaying events with the correct timezone

Ant1D
Motivator

Hi,

I have some data in an index where the events all begin with a UTC timestamp. My Splunk indexer server is in the UK and I would like the timestamps for these events to be interpreted as being in the Splunk indexer timezone (UK) instead of the UTC.

How can I do this?

At present, if a new event arrives at 11AM UK time, the timestamp will say 10AM which is the UTC time so it means that any searches that I do over the last 60 minutes or less will return no results which should not be the case.

Thanks in advance for your help.

1 Solution

Ant1D
Motivator

The solution is to make the following addition to your props.conf file:

[the_sourcetype_name]
TZ = the_timezone_that_your_timestamps_are_in

For this question, you would need to add TZ = UTC

View solution in original post

0 Karma

Ant1D
Motivator

The solution is to make the following addition to your props.conf file:

[the_sourcetype_name]
TZ = the_timezone_that_your_timestamps_are_in

For this question, you would need to add TZ = UTC

0 Karma

whitewool
Splunk Employee
Splunk Employee
0 Karma

Ant1D
Motivator

thanks for the link

0 Karma

Ant1D
Motivator

I tried using the TZ = value attribute before and it didn't work. I guess I can try this again

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi Ant1D

have you check the docs on how to set different timezones?

cheers,

MuS

0 Karma

Ant1D
Motivator

thanks for the link

0 Karma

Ant1D
Motivator

Looks to be working now

0 Karma

Ant1D
Motivator

I tried using the TZ = value attribute before and it didn't work. I guess I can try this again

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...