Splunk Enterprise

How to adjust timestamp for some events sending by UF

NoSpaces
Contributor

Hello for everyone!
I have an UF installed on an MS Exchange server that sends data to the indexer layer
Search actions performed on SearchHeads
All events in the IIS file log (MS Exchange) look like this:
2023-08-22 11:16:36 172.25.57.29 POST bla bla bla...

As you see, a timestamp doesn't have any data about timezone, and on SearchHeads, I see that events are older by 3 hours than I expected to see

I read some questions and documentation about how to adjust the TImeZone and tried to set up props.conf on the UF by setting "TZ = UTC"
Also, I tried another variation, but timestamps didn't change

Another way that I tried is to use "EVAL-_time = _time + 10800"
But this attempt failed too

I think that it is a really common problem, but maybe I missed something and can't solve it. Can anyone help me with this stupid question?

Labels (1)
0 Karma

NoSpaces
Contributor

UP

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...