I have a forwarder that goes by EST. My Splunk server also goes by EST. Today I had to add a source (from a completely different server with UTC time) to my EST Splunk forwarder.
How can I make _time for the logs in this source be in EST? They can still display UTC, but I need to see them in EST for Splunk timing.
I have already tried editing the props.conf to say:
[mdm] TZ = UTC
Where mdm is the sourcetype for this source
You should try to configure splunk to recognize the correct TZ for that source, that way splunk can do all of the search time corrections for you.
As for subtracting 4 hours, not a problem so long as splunk knows it is working with a time.
Timestamp is showing up like this in the raw log...
basically all I want to do is subtract 4 hours from it. Idk how that would go if the UTC time was between midnight and 3:59AM, but I could use temporarily a method to show this time as EST (4 hours prior to what it says now)