Getting Data In

Timezone Configurations

agodoy
Communicator

I have events that are sent in UTC. I have specified in props.conf TZ=UTC for the source. However, when I search for the events they are still being displayed in UTC in the future. I would like to see them in local time. I was reading some of the other questions and it looks like I need to define the local timezone for my Splunk servers.

What is the right way to do this in a Splunk cluster? Do the configs need to be placed in the search peers, search head, all members of the cluster? Would the configs for the local time zone go under the [default] stanza in props.conf?

Thanks

0 Karma
1 Solution

Adrian
Path Finder

Edit the props.conf file in $SPLUNK_HOME/etc/system/local/ or in your own custom application directory in $SPLUNK_HOME/etc/apps/.

The documentation you require is here:
http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Applytimezoneoffsetstotimestamps

There is also a similar question posed with answer here as well:

http://answers.splunk.com/answers/110403/incorrect-event-time-in-splunk

View solution in original post

0 Karma

Adrian
Path Finder

Edit the props.conf file in $SPLUNK_HOME/etc/system/local/ or in your own custom application directory in $SPLUNK_HOME/etc/apps/.

The documentation you require is here:
http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Applytimezoneoffsetstotimestamps

There is also a similar question posed with answer here as well:

http://answers.splunk.com/answers/110403/incorrect-event-time-in-splunk

0 Karma

agodoy
Communicator

I guess the TZ=UTC does not work under the source or sourcetype stanza? It did work under the host stanza.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...