Getting Data In

Timezone configuration with daylight savings time

StefanW
Path Finder

Hello,

since daylight savings time is active we have a time offset for our events.

For example, we use das splunk stream addon to ingest netflow data. 

Within the Events, the timestamp is configured "2021-04-13T05:32:31Z". For my understanding with Z for zulu (UTC)

But if i search for events my _time is 07:32:31. two hours later.. Our timezone is Europe/Berlin.

How can i get this fixed? In the sourcetype of stream_netflow is the timestamp configured to auto.

The OS time from the indexer/search head or universal forwarder are correct to CEST and the time is also correct.

 

We have several other sourcestypes where the time offset is around 1 or 2 hours.

Labels (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!