Getting Data In

Timezone adjustment for IIS logs not working

chocking
Engager

I am new to Splunk and have installed v4.3.4 on a PC and am running searches on IIS logs copied from a server and stored on my local machine (for various reasons I have chosen not to set up a light forwarder on the server yet).

I am finding that the timestamps of the events are not being returned in my local timezone (UTC +11) but are being returned unchanged (UTC).

I tried editing the props.conf file under Splunk\etc\system\local using the following stanza for sourcetype:
[iis-2]
TZ=Australia/Melbourne
(obviously this is not the correct way to change it to the UTC +11 timezone but I was just trying to get any change to the timestamp)

However, this had no effect on the timezone returned by Splunk.
I've removed the stanza, still with no effect.
2012-10-08 08:22:33 (in IIS log)
2012-10-08 08:22:33 (in Splunk event list)

I've been through just about all the timezone questions and answers that I could find.
I presume I am missing something....can anyone suggest what it is? 🙂

Tags (1)
1 Solution

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

View solution in original post

piebob
Splunk Employee
Splunk Employee

chocking, when someone answers your question, please take the time to click the checkbox next to their response to accept the answer (and give them karma)

0 Karma

chocking
Engager

Thanks Skylasam_splunk!
That worked beautifully!
I hadn't attempted that because I had read that IIS logs were treated as UTC by default...looks like Splunk just needed a bit of a helping hand.

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...