Getting Data In

Can you help me change the timezone offset for events that appear to be from the same host?

shariefc
New Member

How do I change the timezone offset for events that appear to be from the same host (but the real host and timezone is contained in the event)?

RAW EVENTS:

Event 1:
host=HOSTA
real_event_host=HOSTX
real_event_time=2018-09-25T06:39:03:142-06:00

Event 2:
host=HOSTA
real_event_host=HOSTY
real_event_time=2018-09-25T08:40:03:142-04:00

Here is how the above events get loaded:

Event 1:
_time=25/09/2018 06:39:03.000 (What I want is for this to now switch to the timezone of the indexer -400 i.e. 25/09/2018 08:39:03.142)
host=HOSTA
real_event_host=HOSTX
real_event_time=2018-09-25T06:39:03:142-06:00

Event 2:
_time=25/09/2018 08:40:03.321 (For this one the timezone is the same so the times should be the same)
host=HOSTA
real_event_host=HOSTY
real_event_time=2018-09-25T08:40:03:321-04:00

**How do I either use the real_event_time as the _time and convert it to the indexer's timezone OR at the very least make the _time reflect the timezone of the event?

HOSTX is in -600 timezone offset
HOSTY is in -400 timezone offset
Both events appear to come from HOSTA which is in -400 timezone offset because HOSTA is a log aggregator**

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...