Getting Data In

Timezone adjustment for IIS logs not working

chocking
Engager

I am new to Splunk and have installed v4.3.4 on a PC and am running searches on IIS logs copied from a server and stored on my local machine (for various reasons I have chosen not to set up a light forwarder on the server yet).

I am finding that the timestamps of the events are not being returned in my local timezone (UTC +11) but are being returned unchanged (UTC).

I tried editing the props.conf file under Splunk\etc\system\local using the following stanza for sourcetype:
[iis-2]
TZ=Australia/Melbourne
(obviously this is not the correct way to change it to the UTC +11 timezone but I was just trying to get any change to the timestamp)

However, this had no effect on the timezone returned by Splunk.
I've removed the stanza, still with no effect.
2012-10-08 08:22:33 (in IIS log)
2012-10-08 08:22:33 (in Splunk event list)

I've been through just about all the timezone questions and answers that I could find.
I presume I am missing something....can anyone suggest what it is? 🙂

Tags (1)
1 Solution

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

View solution in original post

piebob
Splunk Employee
Splunk Employee

chocking, when someone answers your question, please take the time to click the checkbox next to their response to accept the answer (and give them karma)

0 Karma

chocking
Engager

Thanks Skylasam_splunk!
That worked beautifully!
I hadn't attempted that because I had read that IIS logs were treated as UTC by default...looks like Splunk just needed a bit of a helping hand.

skylasam_splunk
Splunk Employee
Splunk Employee

Take a look at - http://splunk-base.splunk.com/answers/43999/iis-ftp-log-timezone-problem - which contains the answer. Set TZ = UTC in /etc/system/local/props.conf

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...