Hi..
I have configured splunk to pick the _time from the logs . i.e that is BST time in my log . but all of a sudden _time is showing the values in IST time .. couldnt understand wat happend suddenly ??
this is timestamp that is available in my log . so ideally _time should be 5/8/13:17:22:11.618 but it is showing as 5/8/13:5:22:11.618 . Previously it used to pick the BST time which is available in log.. Pls help .where i can fix this issue ??
I'm a little confused as IST appears to be 5:30 ahead of BST? but that is a bit more than that.
Anyway, at a first guess have you gone into your user profile and changed your local timezone? Splunk will use this to adjust the timestamp to appear in your local time, so the event may be correct but the displayed time is different.
If the event is now different then your data source has a timestamping issue