Getting Data In

Timestamp setting

Motivator

Hey,

I have an index where each event starts with a UTC timestamp. It is using this UTC timestamp for the _time field. Instead I would like for all events in this index to use the Splunk server timezone for the _time field. How can I configure Splunk to do this?

Thanks.

0 Karma
1 Solution

Motivator
0 Karma

Motivator
0 Karma

Motivator

the former please. Thanks

0 Karma

Path Finder

You could try to assign the timezone in your props.conf

0 Karma

Splunk Employee
Splunk Employee

are you saying you want the timestamp interpreted as if it were in the Splunk indexer timezone instead of in UTC, or do you mean you want to display the (UTC) timestamp in the Splunk server timezone?

0 Karma