Getting Data In

Timezone adjustment for IIS logs not working

chocking
Engager

I am new to Splunk and have installed v4.3.4 on a PC and am running searches on IIS logs copied from a server and stored on my local machine (for various reasons I have chosen not to set up a light forwarder on the server yet).

I am finding that the timestamps of the events are not being returned in my local timezone (UTC +11) but are being returned unchanged (UTC).

I tried editing the props.conf file under Splunk\etc\system\local using the following stanza for sourcetype:
[iis-2]
TZ=Australia/Melbourne
(obviously this is not the correct way to change it to the UTC +11 timezone but I was just trying to get any change to the timestamp)

However, this had no effect on the timezone returned by Splunk.
I've removed the stanza, still with no effect.
2012-10-08 08:22:33 (in IIS log)
2012-10-08 08:22:33 (in Splunk event list)

I've been through just about all the timezone questions and answers that I could find.
I presume I am missing something....can anyone suggest what it is? 🙂

Tags (1)
1 Solution

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

View solution in original post

piebob
Splunk Employee
Splunk Employee

chocking, when someone answers your question, please take the time to click the checkbox next to their response to accept the answer (and give them karma)

0 Karma

chocking
Engager

Thanks Skylasam_splunk!
That worked beautifully!
I hadn't attempted that because I had read that IIS logs were treated as UTC by default...looks like Splunk just needed a bit of a helping hand.

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...