Hi there,
I have an application that is incorrectly reporting the current timezone is GMT -0500 with timestamps of the following form:
[29/Oct/2010:15:59:50 -0500]
(Currently we're on EDT which is -0400)
Is there a way i can accept the timestamp but ignore the offset? Currently all events are marked an hour in the future?
Thanks!
You can set an explicit time format in props.conf
and leave the timezone offset out.
Take a look at:
http://www.splunk.com/base/Documentation/latest/Admin/Configuretimestamprecognition
and look specifically at the TIME_FORMAT option.
You can set an explicit time format in props.conf
and leave the timezone offset out.
Take a look at:
http://www.splunk.com/base/Documentation/latest/Admin/Configuretimestamprecognition
and look specifically at the TIME_FORMAT option.
Awesome. Thank you!