HI,
Splunk Version : Splunk 6.1.1
Splunk Universal forwarder : version 5.0.4
I see the field 'date_zone' has values '0' & 'local'
I searched for the default timezone extraction field in props.conf, but i couldn't
How do i change this to specific time zone ? like UTC, GMT
Please advise.
Hi splunker12er,
date_zone is the offset from GMT in minutes or local if you're in the same TZ. It will not show the TZ itself.
See the docs about the default fields for more information on this.
Cheers, MuS
Hi splunker12er,
date_zone is the offset from GMT in minutes or local if you're in the same TZ. It will not show the TZ itself.
See the docs about the default fields for more information on this.
Cheers, MuS
documentation has been removed. This is messing up my timecharts. Can someone recommend how to remove this?