Getting Data In

Unable to recognize the correct timezone from Forwarder on Windows OS

yuwtennis
Communicator

Hi !

I am having problem collecting logs from windows server 2008R2 .
The timezone are always the same with the one on Splunk server (ver 5.0.5).

I have tried to use TZ setting with host stanza but didn't work. But I confirmed that
if you force to change the _time with EVAL parameter in props.conf it does work.

[host::WIN-M02LJSSWVMU]

TZ = UTC

EVAL-_time = _time- 32400

I appreciate if someone can share workaround to make splunk server recognize the timezone
correctly from the forwarder on windows OS.

I asked this question because I wasn't sure if the below link is already commited to splunk or not.
http://answers.splunk.com/answers/9747/are-windows-eventlogs-from-windows-forwarder-lacking-timezone

0 Karma

uuppuluri_splun
Splunk Employee
Splunk Employee

An enhancement request has been filed but no commit yet

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...