I have a timestamp in a format I havn't dealt with before and I am struggling to get it converted to my timezone using the offset. In raw event form it is like this:
I have also attached a screenshot of how splunk is indexing it.
My second question is how would I configure the sourcetype to have splunk use TimeGenerated field as _time automatically? I've attached a second screenshot with the sourcetype as well.
Any help or links would be greatly appreciated!
I have attempted your suggestion and ingested some more data:
Unfortunately it doesn't look like it has updated _time correctly:
Would these settings have any impact as well?
Appreciate your help, thanks mate