Getting Data In

Unable to recognize the correct timezone from Forwarder on Windows OS

yuwtennis
Communicator

Hi !

I am having problem collecting logs from windows server 2008R2 .
The timezone are always the same with the one on Splunk server (ver 5.0.5).

I have tried to use TZ setting with host stanza but didn't work. But I confirmed that
if you force to change the _time with EVAL parameter in props.conf it does work.

[host::WIN-M02LJSSWVMU]

TZ = UTC

EVAL-_time = _time- 32400

I appreciate if someone can share workaround to make splunk server recognize the timezone
correctly from the forwarder on windows OS.

I asked this question because I wasn't sure if the below link is already commited to splunk or not.
http://answers.splunk.com/answers/9747/are-windows-eventlogs-from-windows-forwarder-lacking-timezone

0 Karma

uuppuluri_splun
Splunk Employee
Splunk Employee

An enhancement request has been filed but no commit yet

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...