We have Splunk instances running in EST, however the application log files are in GMT & EST.
When Splunk is indexing the log files in GMT , the time and the timestamp in the event both are showing up in GMT in search.
So, as per the requirement, we are editing the props.conf file to make the time in EST and timestamp in the event in GMT.
I would like to know what is the best practice and is there a global change i can do to fix the timestamp for all the events in Splunk instance to make them in EST regardless of the log file timestamp?
... View more