Splunk Search

Splunk and timezones

tb5821
Communicator

In our splunk instance I believe the props.config file is set to UTC as that is what most of our logs are in but we do have some that are in the local time zone. Since I do not have access to edit the props file is there a way to specify in search that all these logs should be considered EST?

Tags (2)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Not really. You can of course compute the difference yourself, but the timestamp (along with host/source/sourcetype, and event breaks) is one of the only things that actually needs to be specified correctly when the data is indexed. Basically, if you don't index with the correct time zone (which means the correct time) then the data can't be found under the correct time. Your admin needs to fix the input data, as basically right now, it's wrong.

linu1988
Champion

If you can calculate and evaluate the time difference, the search result will come as you want.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...