Splunk Enterprise

How do you change timezone of the Splunk forwarder?

rohith3e
New Member

Hi,

The timezones of the event time and Splunk light time are different. How can I change the time zone of the events(Splunk forwarder)?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The forwarder does not provide time information. That will come from the event itself. The props.conf settings on your indexers should say how to interpret time for the sourcetype. If time zone information is not included, you can use the TZ attribute in props.conf to specify it.

---
If this reply helps you, an upvote would be appreciated.
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!