Good evening. I have a ASCII event message that looks like the following: The timestamp is in GMT time. When Splunk coverts the timestamp the result is off by 5 hours. For this event message, the resulting timestamp is "11/11/20 5:46:39.969 PM" but should really be "11/11/20 12:46:39.969 PM". I have the servers local time zone set to "UTC -5 Eastern Time". I already created a "props.conf" file and placed the following "TZ=Etc/GMT0", but it did not change the Splunk time stamp. INFO Stol 20-314-17:46:39.969: !!!!!!!!!INST Telemetry Started !!!!!! Thank for your assistance.
... View more