We have standardized our infrastructure on UTC, but we want to generate reports in PST. Is there a way to specify a timezone transform at search time such that the events themselves don’t need to be modified? the link below would change the actual messages as they come in and I want to keep the data in splunk and my various raw syslog messages consistent.
http://www.splunk.com/base/Documentation/4.1.3/Admin/Applytimezoneoffsetstotimestamps