All of my splunk events have the timestamp GMT. How do I evaluate _time to show EST? I was thinking of using:
eval n=strftime(_time, "%H:%M %d/%m/%y %Z")
But have it be in EST instead of GMT?
many answers in this portal, here are couple:
also in docs:
if it only apply to you as a user, you can change your user default time zone to EST and you supposed to see timestanps as EST
hope it helps