Getting Data In

Yet more timezone excitement

sseekamp
Explorer

I have logs with a timezone specified like:

2014 Apr 30 20:37:31:001 GMT -5

There is a space between the GMT and the -5. Splunk is picking this up as GMT instead of US/Central.

How can I override or define the TZ as the entire "GMT -5" string?

Thanks!

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Add following to your props.conf

[YourSourceType]
TIME_FORMAT=%Y %b %d %H:%M:%S:%3Q %Z %z  
....
.other settings..
.....

View solution in original post

somesoni2
Revered Legend

Add following to your props.conf

[YourSourceType]
TIME_FORMAT=%Y %b %d %H:%M:%S:%3Q %Z %z  
....
.other settings..
.....

sseekamp
Explorer

Thanks - this was perfect!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You could put a TIME_FORMAT string in your props.conf file, but I think that won't work because the offset is not in the expected 'hhmm' format. Try overriding the timezone by putting TZ=-05:00 in the relevant props.conf stanza.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...