I have indexer in UTC+3 timezone and universal forwarder on syslog server in UTC+6 timezone. I tried to set up timezone recognition and set TZ = Asia/Novosibirsk
in props.conf for [sourcetype::syslog]
.
But when I'm trying to search events (user which I use also has UTC+3) time setting I see UTC+6 time in _time
field.
Please help me to fix this.
what is your date_zone
field's value for these events? If it is "+300" then it is working. I do not understand what you mean when you say "I see ... in the _time field"