Getting Data In

forwarder source logs displaying in UTC Time - Need EST

bcusick
Communicator

Hi,

I have a forwarder that goes by EST. My Splunk server also goes by EST. Today I had to add a source (from a completely different server with UTC time) to my EST Splunk forwarder.

How can I make _time for the logs in this source be in EST? They can still display UTC, but I need to see them in EST for Splunk timing.

I have already tried editing the props.conf to say:

[mdm]
TZ = UTC

Where mdm is the sourcetype for this source

Thanks,

Brian

0 Karma

woodcock
Esteemed Legend

The indexers were probably rebooted which is required for this change to take effect.

0 Karma

bcusick
Communicator

Somehow this issue has cleared itself up. 🙂

0 Karma

lukejadamec
Super Champion

You should try to configure splunk to recognize the correct TZ for that source, that way splunk can do all of the search time corrections for you.

As for subtracting 4 hours, not a problem so long as splunk knows it is working with a time.

0 Karma

bcusick
Communicator

Timestamp is showing up like this in the raw log...

2014-03-11 18:04:11

basically all I want to do is subtract 4 hours from it. Idk how that would go if the UTC time was between midnight and 3:59AM, but I could use temporarily a method to show this time as EST (4 hours prior to what it says now)

0 Karma

lukejadamec
Super Champion

Do the event timestamps include a timezone, or is the timestamp an epoch time?
How did you add the new server to the forwarder, and why not add it directly to the indexer?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...