Splunk Search
Highlighted

How to convert GMT timestamp to EST?

Communicator

All of my splunk events have the timestamp GMT. How do I evaluate _time to show EST? I was thinking of using:

eval n=strftime(_time, "%H:%M %d/%m/%y %Z")

But have it be in EST instead of GMT?

0 Karma
Highlighted

Re: How to convert GMT timestamp to EST?

SplunkTrust
SplunkTrust
0 Karma