- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to convert GMT timestamp to EST?
kdimaria
Communicator
04-03-2018
05:46 AM
All of my splunk events have the timestamp GMT. How do I evaluate _time to show EST? I was thinking of using:
eval n=strftime(_time, "%H:%M %d/%m/%y %Z")
But have it be in EST instead of GMT?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

adonio
Ultra Champion
04-03-2018
05:58 AM
Hello there,
many answers in this portal, here are couple:
https://answers.splunk.com/answers/4279/timezone-and-timestamp-modification-at-search-report-time.ht...
https://answers.splunk.com/answers/58027/change-timezone-of-logs.html
also in docs:
https://docs.splunk.com/Documentation/Splunk/7.0.3/Data/Applytimezoneoffsetstotimestamps
https://docs.splunk.com/Documentation/Splunk/7.0.3/SearchReference/Commontimeformatvariables
if it only apply to you as a user, you can change your user default time zone to EST and you supposed to see timestanps as EST
hope it helps
