Getting Data In

Timezone adjustment for IIS logs not working

chocking
Engager

I am new to Splunk and have installed v4.3.4 on a PC and am running searches on IIS logs copied from a server and stored on my local machine (for various reasons I have chosen not to set up a light forwarder on the server yet).

I am finding that the timestamps of the events are not being returned in my local timezone (UTC +11) but are being returned unchanged (UTC).

I tried editing the props.conf file under Splunk\etc\system\local using the following stanza for sourcetype:
[iis-2]
TZ=Australia/Melbourne
(obviously this is not the correct way to change it to the UTC +11 timezone but I was just trying to get any change to the timestamp)

However, this had no effect on the timezone returned by Splunk.
I've removed the stanza, still with no effect.
2012-10-08 08:22:33 (in IIS log)
2012-10-08 08:22:33 (in Splunk event list)

I've been through just about all the timezone questions and answers that I could find.
I presume I am missing something....can anyone suggest what it is? 🙂

Tags (1)
1 Solution

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

View solution in original post

piebob
Splunk Employee
Splunk Employee

chocking, when someone answers your question, please take the time to click the checkbox next to their response to accept the answer (and give them karma)

0 Karma

chocking
Engager

Thanks Skylasam_splunk!
That worked beautifully!
I hadn't attempted that because I had read that IIS logs were treated as UTC by default...looks like Splunk just needed a bit of a helping hand.

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...