Getting Data In

What is the best way to adjust the time value for incoming syslog events from a specific host

ntaylorsplunk
Explorer

I have a one host that has a time offset of +5 hours and would rewrite the timestamp to represent the local time zone before the event is indexed. What's the best way to do this?

Tags (1)
0 Karma

lukejadamec
Super Champion

You would use the TZ parameter in props.conf
Here is a link to the documentation:

http://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps

ntaylorsplunk
Explorer

Forgot to mention, there is no timezone or offset information in the timestamp... The timestamp format from the incoming event is %b %d %T

0 Karma

Masa
Splunk Employee
Splunk Employee

No need to have timezone information in events. As lukejadamec is saying, you can make use of TZ attribute

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...