since daylight savings time is active we have a time offset for our events.
For example, we use das splunk stream addon to ingest netflow data.
Within the Events, the timestamp is configured "2021-04-13T05:32:31Z". For my understanding with Z for zulu (UTC)
But if i search for events my _time is 07:32:31. two hours later.. Our timezone is Europe/Berlin.
How can i get this fixed? In the sourcetype of stream_netflow is the timestamp configured to auto.
The OS time from the indexer/search head or universal forwarder are correct to CEST and the time is also correct.
We have several other sourcestypes where the time offset is around 1 or 2 hours.