Is there a way to specify a timezone in a datanmodel?
I have an eval field called date relying on Splunk's _time field but I want to ensure that it matches a specific timezone, rather than relying on the extracted _time of the log as its in UTC.
I want to have the timezone match Brisbane, Australia (+10)
Timezone is applied at search time based on the users' settings. If none is set for the user Splunk will use the TZ of the server (default).
This doesn't help in my instance because even though my timezone is set to mine, when doing a tstats datamodel the timezone is UTC no matter my settings