I have logs with a timezone specified like:
2014 Apr 30 20:37:31:001 GMT -5
There is a space between the GMT and the -5. Splunk is picking this up as GMT instead of US/Central.
How can I override or define the TZ as the entire "GMT -5" string?
Thanks!
Add following to your props.conf
[YourSourceType]
TIME_FORMAT=%Y %b %d %H:%M:%S:%3Q %Z %z
....
.other settings..
.....
Add following to your props.conf
[YourSourceType]
TIME_FORMAT=%Y %b %d %H:%M:%S:%3Q %Z %z
....
.other settings..
.....
Thanks - this was perfect!
You could put a TIME_FORMAT string in your props.conf file, but I think that won't work because the offset is not in the expected 'hhmm' format. Try overriding the timezone by putting TZ=-05:00
in the relevant props.conf stanza.