I have an index where each event starts with a UTC timestamp. It is using this UTC timestamp for the _time field. Instead I would like for all events in this index to use the Splunk server timezone for the _time field. How can I configure Splunk to do this?
are you saying you want the timestamp interpreted as if it were in the Splunk indexer timezone instead of in UTC, or do you mean you want to display the (UTC) timestamp in the Splunk server timezone?