Hello @scelikok I have given, [host::hostname] SHOULD_LINEMERGE = true LINE_BREAKER = ([\r\n]+) MAX_TIMESTAMP_LOOKAHEAD = 128 NO_BINARY_CHECK = true CHARSET = UTF-8 disabled = false TIME_FORMAT = %Y-%m-%d %H:%M:%S.%Q TZ = Asia/Dubai But the logs from that particular host is getting indexed in UTC timings. The server time zone has been set to UTC and that cannot be changed. Is there anything we can do from Splunk end? I already been tried to point the time zone to datetime.xml file in the HF, but no luck.
... View more