I'm having an issue with the data pulled in by the Splunk Add-on for ServiceNow. Timestamps of events are converted to UTC instead of CET. I've tried to set up a props.conf for the add-on like this:
But no luck. Time of the sys_updated_on is still 2 hours off.
... View more