Splunk Search

How to convert time in another timezone?

bosseres
Communicator

Hello everyone!

I have time in such format 2022-09-02T18:44:15, this time in GMT+3, and I need to change convert this time to UTC. Can you help me? 

Labels (1)
0 Karma

PickleRick
Ultra Champion

Depends on what you mean by "I have time in such format". Is this how the time is formatted in the raw event? In this case you should fix your parsing configuration so that the source timezone is taken into account.

When you have your timestamp properly parsed, it's displayed in your user's configured timezone.

So properly it should work like that (for example):

1. Your source is in UTC+3 and sends the timestamp as 13:07

2. Splunk parses it and stores it as an absolute timestamp which is 10:07 UTC

3. Your user has his time zone configured as UTC+5 and splunk renders the time for him as 15:07 because that's his local zone.

0 Karma

bosseres
Communicator

did with | eval utc = _time-10800 and then strftime.

Problem is solved, but if there is any other suggestions of better realizations, would be glad to look.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

There is a function relative_time().  The only advantage is to be more obvious about the intention.

 

_time = relative_time(_time, -3h)

 

 But even this is not semantically faithful to a time zone conversion.  It would be better if your data source can signal that it uses a zone that is UTC+3 so Splunk can automatically record in true UTC epoc.  If you have any control over input, How timestamp assignment works describes some methods you can affect indexing even when you cannot change log format. (The best, of course, is still to persuade developers to record timezone properly.)

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...