Splunk Search

date_zone field

EricPartington
Communicator

I am trying to make sure my timezones for devices logging to splunk are correct. I have noticed as part of the date extractions that there is a field called date_zone.
the values for all my devices are 'local'.
what is this field extracting and should it reference GMT or UTC if that timezone indicator is in the timestamp on the syslog message?

1 Solution

hexx
Splunk Employee
Splunk Employee

This Splunk-internal index-time field will take one of two values :

  • A time zone offset in minutes from UTC. This will only be available if 1) Splunk has found a time zone offset or name in the event rawdata or 2) a TZ setting is specified for the data in scope in props.conf
  • The string "local" which indicates that Splunk found no information regarding the time zone of the event and attributed to it the time zone of the instance where event parsing occurred (usually, the indexer).

View solution in original post

hexx
Splunk Employee
Splunk Employee

This Splunk-internal index-time field will take one of two values :

  • A time zone offset in minutes from UTC. This will only be available if 1) Splunk has found a time zone offset or name in the event rawdata or 2) a TZ setting is specified for the data in scope in props.conf
  • The string "local" which indicates that Splunk found no information regarding the time zone of the event and attributed to it the time zone of the instance where event parsing occurred (usually, the indexer).

tlmayes
Contributor

I am attempting to solve the same problem: "trying to make sure my timezones for devices logging to splunk are correct". All of my remote UF's are reporting the correct date_zone data, but wish to convert date_zone to TZ (CST instead of +0600). Any idea how to accomplish this? All of my attempts end with Splunk making the decision the result is ALWAYS tied to my browser (I know, is designed this way)

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...