We have an environment with a mix of light/heavy forwarders, a deployment server, an indexer, and multiple apps. If I want to set the timezone for a group of servers which props.conf (or other) do I set the TZ = X in? The indexer global, indexer app, deployment server, or forwarder itself?

There is a great article on the Splunk wiki: Where do I configure my Splunk settings
The timezone setting goes in props.conf. It MUST be set where the data is parsed, so that means the heavy forwarders AND the indexers. See this answer from S Sorkin; all Sorkin answers are definitive.


I would do this on the indexer to keep it simple, but as always there are many ways leading to Rome.