Getting Data In

Yet more timezone excitement

sseekamp
Explorer

I have logs with a timezone specified like:

2014 Apr 30 20:37:31:001 GMT -5

There is a space between the GMT and the -5. Splunk is picking this up as GMT instead of US/Central.

How can I override or define the TZ as the entire "GMT -5" string?

Thanks!

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Add following to your props.conf

[YourSourceType]
TIME_FORMAT=%Y %b %d %H:%M:%S:%3Q %Z %z  
....
.other settings..
.....

View solution in original post

somesoni2
Revered Legend

Add following to your props.conf

[YourSourceType]
TIME_FORMAT=%Y %b %d %H:%M:%S:%3Q %Z %z  
....
.other settings..
.....

sseekamp
Explorer

Thanks - this was perfect!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You could put a TIME_FORMAT string in your props.conf file, but I think that won't work because the offset is not in the expected 'hhmm' format. Try overriding the timezone by putting TZ=-05:00 in the relevant props.conf stanza.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...