Getting Data In

Hong Kong Timezone HKT not being recognised ?

mzorzi
Splunk Employee
Splunk Employee

If I index an event with

2015-05-20 19:10:01.132 HKT This is an event  in Hong Kong Time Zone

The timezone will not be recognized. If instead the event is

2015-05-20 19:10:01.132 HongKong This is an event  in Hong Kong Time Zone

The timezone will be recognized. However the HKT is commonly used across my devices. How do I get Splunk to recognize HKT?

Tags (1)
0 Karma

mzorzi
Splunk Employee
Splunk Employee

This is a known issue which will be solved with Splunk 6.2.4

There is an easy workaround to have this working on the current release:

1. mkdir $SPLUNK_HOME/share/splunk/zoneinfo

2. ( Assuming the Indexer is a Linux box )  cp /usr/share/zoneinfo/Hongkong $SPLUNK_HOME/share/splunk/zoneinfo/HKT

3. Restart Splunk.

And it will recognize the HKT timezone correctly.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...