Hi @hemendralodhi ,
When Splunk writes a timestamp to an index at index time, it gets written as an epoch time value, which is unaware of time zone information. At that point, it is up to the search head to present that epoch time value in way that is relevant to the time zone of the user.
As per the docs (https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf) your time zone setting in props.conf of TZ = UTC does not do anything because there is time zone information in the event itself, which takes precedence.
From your image, it looks like the event is being displayed by a user who has their time zone set to GMT (UTC). But it's also confusing because the date_zone value suggests that the events have been written as GMT+11:00. There is something odd going on there. If it were written as GMT+11:00 the time stamp in your event would not match the event time value.
I understand that you may not want to set the time zone in the web interface, but that is the best way to do it. If you modify the timestamp values as they're written at index time, you're not going to have good results down the road because this is not best practice, and is inconsistent with the way Splunk tracks time.
If the search head is set as AEDT, then by default any user who does not set his time zone setting will be using the time zone of the search head.
... View more