Getting Data In

Unable to recognize the correct timezone from Forwarder on Windows OS

yuwtennis
Communicator

Hi !

I am having problem collecting logs from windows server 2008R2 .
The timezone are always the same with the one on Splunk server (ver 5.0.5).

I have tried to use TZ setting with host stanza but didn't work. But I confirmed that
if you force to change the _time with EVAL parameter in props.conf it does work.

[host::WIN-M02LJSSWVMU]

TZ = UTC

EVAL-_time = _time- 32400

I appreciate if someone can share workaround to make splunk server recognize the timezone
correctly from the forwarder on windows OS.

I asked this question because I wasn't sure if the below link is already commited to splunk or not.
http://answers.splunk.com/answers/9747/are-windows-eventlogs-from-windows-forwarder-lacking-timezone

0 Karma

uuppuluri_splun
Splunk Employee
Splunk Employee

An enhancement request has been filed but no commit yet

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...