Hi,
I am using Splunk Cloud and we are getting all the logs in IST timezone when IST is my preferred time zone.
there are some of the logs reporting in UTC time zone and the logs we are getting to search head via UTC time zone. i wanted UTC time zone to reflect as IST.
Can you please help me in this way.
if the way is to use TZ attribute in props.conf what will be the value for TZ attribute. Please let me know.
props.conf must be edited in HF or indexer?
Thanks in advance
Hi @umesh
you can set TZ=IST in props.conf in UF
you can apply timezone seeting based on host/source/sourcetype
according to your data please use relevant name and once changes are done restart the UF to take effect
[host::<hostname>] TZ = IST