Hello, I recently enabled a SolarWinds alert in the inputs.conf on the heavy forwarder. The data is now ingesting into Splunk, but the timestamps are appearing in UTC instead of local time. The interval is set to 899. All other SolarWinds alerts ingesting into Splunk are showing the correct local time, so this issue seems isolated to the newly enabled alert. Any guidance on what might cause this specific alert to default to UTC—whether related to the alert configuration, timestamp parsing, or a missing props/transforms setting—would be appreciated.
... View more