Getting Data In

Timezone adjustment for IIS logs not working

chocking
Engager

I am new to Splunk and have installed v4.3.4 on a PC and am running searches on IIS logs copied from a server and stored on my local machine (for various reasons I have chosen not to set up a light forwarder on the server yet).

I am finding that the timestamps of the events are not being returned in my local timezone (UTC +11) but are being returned unchanged (UTC).

I tried editing the props.conf file under Splunk\etc\system\local using the following stanza for sourcetype:
[iis-2]
TZ=Australia/Melbourne
(obviously this is not the correct way to change it to the UTC +11 timezone but I was just trying to get any change to the timestamp)

However, this had no effect on the timezone returned by Splunk.
I've removed the stanza, still with no effect.
2012-10-08 08:22:33 (in IIS log)
2012-10-08 08:22:33 (in Splunk event list)

I've been through just about all the timezone questions and answers that I could find.
I presume I am missing something....can anyone suggest what it is? 🙂

Tags (1)
1 Solution

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

View solution in original post

piebob
Splunk Employee
Splunk Employee

chocking, when someone answers your question, please take the time to click the checkbox next to their response to accept the answer (and give them karma)

0 Karma

chocking
Engager

Thanks Skylasam_splunk!
That worked beautifully!
I hadn't attempted that because I had read that IIS logs were treated as UTC by default...looks like Splunk just needed a bit of a helping hand.

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...