Getting Data In

change extracted event timezone

davidepala
Path Finder

Hi guys
i've a scritpt on a linux forwarder to monitor a load balancer, it's log is a txt file in UTC format, i need to set the time zone to europe/rome, to do this i've setup props.conf on indexer as show below

[source::NSowa]
TZ = Europe/Rome

the result is the same

alt text

as you can see event without timestam are logged with the correct time, the time extraction is wrong.

1 Solution

davidepala
Path Finder

Solved .... the time zone must be the TZ of the SOURCE .... in my case W3C log are always UTC, using TZ = UTC i've solved the problem

View solution in original post

0 Karma

davidepala
Path Finder

Solved .... the time zone must be the TZ of the SOURCE .... in my case W3C log are always UTC, using TZ = UTC i've solved the problem

0 Karma

davidepala
Path Finder

alt text

here is the screenshot with source as selected field

0 Karma

ddrillic
Ultra Champion

Based on this screen-shot, these two events don't seem be of source = NSowa. You see, source is not listed below the event, only host...

0 Karma

davidepala
Path Finder

tnx ddrillic, the source is correct, i don't know why but i've hosted a new screenshot on imgur but the forum don't show it ... i've post a new reply in the main thread with screenshot

0 Karma

davidepala
Path Finder

i've read the documentation, I read about the TZ parameter there ... where i'm wrong?

0 Karma

micahkemp
Champion

My apologies, I didn't see the props.conf snippet you posted. I read this as a general "how do I use TZ in Splunk" question. @ddrillic's comment seems to identify at least one issue with this configuration.

0 Karma

micahkemp
Champion

Consult the documentation for instruction on setting the timezone correctly.

klopez30
Explorer

I downvoted this post because this isn't a very helpful comment. telling someone to just read the documentation doesn't help someone find what they're looking for to become better.

0 Karma

493669
Super Champion

We should not be trying to discourage people from posting answers..down votes are for completely wrong answers/bad advice

0 Karma

micahkemp
Champion

I get the reasoning behind the downvote. I think it's the type of post that should potentially be downvoted (when it an answer is purposely unhelpful, etc). In this case I simply misunderstood the question, and apologized to the asker prior to the downvote.

When I posted the answer, a pointer to the correct documentation seemed like the best place to start, due to my missing the details in the question about already having attempted to implement the configs.

All in all, it was a reasonable consideration to downvote.

0 Karma

micahkemp
Champion

As I responded in a previous comment, it seemed to be a general "how do I configure timezones to work" question. As such, I linked to the documentation in my answer.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...