I think i'm going mad.
I'm a brand new user who's eval-ing splunk, seems powerful but i'd like to get all my logs in time order to show app + iis events together. I have a IIS 6.0 web and have manually imported the logs into splunk using the add data and choosing iis logs.
I've created a blank props.conf file in the \etc\local directory.
in that file is only this:
[iis-2]
TZ = GMT
restart splunk and no change. I've also tried:
[sourcetype::iis-2]
TZ = GMT - even tried using Africa/Sao_Tome
i've also wildcarded the iis-2 with iis*.
Nothing seems to work. Do i need to delete all the data for the change to take affect? am i missing something -- very likely!
thanks in advance for any and all assistance!
... View more