Getting Data In

WebLogic add-on is not parsing UTC time zone correctly but does correct with GMT

seva98
Path Finder

I've discovered issue with WebLogic add-on (1.0.0) for Splunk and I am having hard time figuring out how to fix props.conf to parse timestamp correctly.

My Splunk instance is in CEST. There is string with timezone after timestamp and CEST/GMT are parsed correctly but UTC is not.

Server #1 - Correct

 

 

####<Oct 5, 2022 5:00:21 PM CEST> <Info> ...

Parsed timestamp: 10/5/22 5:00:21.000 PM

 

 

 

Server #2 - correct

 

 

####<Oct 5, 2022 3:24:11 PM GMT> <Info> ...

Parsed timestamp: 10/5/22 5:24:11.000 PM

 

 

 

Server #3 - incorrect

 

 

####<Oct 5, 2022 4:30:23 PM UTC> <Info>

Parsed timestamp: 10/5/22 4:30:23.000 PM
Should be: 10/5/22 6:30:23.000 PM

 

 

 

  

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...