I have this issue as well but without the benefit of logs in GMT. My logs are multiple time zones in a single host, index, source, sourcetype combo. Here's an example: { [-]
AppID:
ElapsedSeconds: 0.694 seconds
Event: RestCall
Method: POST
Request: { [+]
}
RequestLength: 371
RequestTimestamp: 16-Nov-2022 12:59:54
Response: { [+]
}
ResponseLength: 286
ResponseTimestamp: 16-Nov-2022 12:59:55
SequenceNumber: null
ServiceName:
ServiceURL:
StatusCode: 200
StatusText: OK
TimeZone: Asia/Shanghai
UserID:
UserIP: 127.0.0.1
UserName:
} In total there are about 85 different timezones logging here. Any idea how to get Splunk to recognize the timezone when not with the time stamp?
... View more