Splunk Search

date_zone field

EricPartington
Communicator

I am trying to make sure my timezones for devices logging to splunk are correct. I have noticed as part of the date extractions that there is a field called date_zone.
the values for all my devices are 'local'.
what is this field extracting and should it reference GMT or UTC if that timezone indicator is in the timestamp on the syslog message?

1 Solution

hexx
Splunk Employee
Splunk Employee

This Splunk-internal index-time field will take one of two values :

  • A time zone offset in minutes from UTC. This will only be available if 1) Splunk has found a time zone offset or name in the event rawdata or 2) a TZ setting is specified for the data in scope in props.conf
  • The string "local" which indicates that Splunk found no information regarding the time zone of the event and attributed to it the time zone of the instance where event parsing occurred (usually, the indexer).

View solution in original post

hexx
Splunk Employee
Splunk Employee

This Splunk-internal index-time field will take one of two values :

  • A time zone offset in minutes from UTC. This will only be available if 1) Splunk has found a time zone offset or name in the event rawdata or 2) a TZ setting is specified for the data in scope in props.conf
  • The string "local" which indicates that Splunk found no information regarding the time zone of the event and attributed to it the time zone of the instance where event parsing occurred (usually, the indexer).

tlmayes
Contributor

I am attempting to solve the same problem: "trying to make sure my timezones for devices logging to splunk are correct". All of my remote UF's are reporting the correct date_zone data, but wish to convert date_zone to TZ (CST instead of +0600). Any idea how to accomplish this? All of my attempts end with Splunk making the decision the result is ALWAYS tied to my browser (I know, is designed this way)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Cloud Application Management in Terraform

Now On-Demand   We’re diving into how you can bring Infrastructure as Code (IaC) principles to your Splunk ...

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...