Getting Data In

WebLogic add-on is not parsing UTC time zone correctly but does correct with GMT

seva98
Path Finder

I've discovered issue with WebLogic add-on (1.0.0) for Splunk and I am having hard time figuring out how to fix props.conf to parse timestamp correctly.

My Splunk instance is in CEST. There is string with timezone after timestamp and CEST/GMT are parsed correctly but UTC is not.

Server #1 - Correct

 

 

####<Oct 5, 2022 5:00:21 PM CEST> <Info> ...

Parsed timestamp: 10/5/22 5:00:21.000 PM

 

 

 

Server #2 - correct

 

 

####<Oct 5, 2022 3:24:11 PM GMT> <Info> ...

Parsed timestamp: 10/5/22 5:24:11.000 PM

 

 

 

Server #3 - incorrect

 

 

####<Oct 5, 2022 4:30:23 PM UTC> <Info>

Parsed timestamp: 10/5/22 4:30:23.000 PM
Should be: 10/5/22 6:30:23.000 PM

 

 

 

  

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...