Getting Data In

TZ Settings

trumpjk
Explorer

I have systems that forward logs via syslog-ng to my splunk server. Systems are in different TZ's mix of EDT and GMT my splunk server/indexer is in EDT. I have the TZ offset displayed in log entries being sent to splunk server. Two questions will splunk read TZ offset and display indexed entries in EDT without me having to put an entry for each host in the props.conf? If splunk will do automatically is there a certain postion the TZ offset has to be in? Current format: Sep 6 15:38:14 hostname +00:00

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

You can use a regex to match a set of hosts...have you looked at specify time zones of timestamps in the Getting Data In manual? The example there is pretty close to your situation, if I am understanding you correctly.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...