I am trying to make sure my timezones for devices logging to splunk are correct. I have noticed as part of the date extractions that there is a field called date_zone.
the values for all my devices are 'local'.
what is this field extracting and should it reference GMT or UTC if that timezone indicator is in the timestamp on the syslog message?
This Splunk-internal index-time field will take one of two values :
This Splunk-internal index-time field will take one of two values :
I am attempting to solve the same problem: "trying to make sure my timezones for devices logging to splunk are correct". All of my remote UF's are reporting the correct date_zone data, but wish to convert date_zone to TZ (CST instead of +0600). Any idea how to accomplish this? All of my attempts end with Splunk making the decision the result is ALWAYS tied to my browser (I know, is designed this way)