I am getting some data from docker application. Client is telling me that in his log file the time stamp is up to date but when it comes to splunk, its 4 hours behind.
On indexer, I have created the props.conf file and have the following entry
TZ = US/Eastern
How can I fix this?