Refer to the list of tz database time zones for all permissible time zone values.
My question: Given a search statement such as
strptime(SLA." ".timeZone, "%H:%M %Z")
Does Splunk have any built-in time zone database that might require periodic updates as for instance, when a locale changes its standard to daylight saving dates, or does Splunk simply use the database that's baked into a lower layer of the stack?
It depends on your platform. See https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Applytimezoneoffsetstotimestamps#zoneinfo_.2...
View solution in original post
That wraps it up perfectly; thanks!
I’m not sure why that little nugget was so hard (for me at least) to find. “Getting Data In” was not where I expected it to show up, since we were looking at search-time strptime().