Splunk Enterprise

How do you change timezone of the Splunk forwarder?

New Member


The timezones of the event time and Splunk light time are different. How can I change the time zone of the events(Splunk forwarder)?

0 Karma


The forwarder does not provide time information. That will come from the event itself. The props.conf settings on your indexers should say how to interpret time for the sourcetype. If time zone information is not included, you can use the TZ attribute in props.conf to specify it.

If this reply helps you, an upvote would be appreciated.
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!