To be honest I do not know how its configuration should be done, I follow someone who seems to experience something similar to me https://answers.splunk.com/answers/555414/how-to-edit-propsconf-to-ignore-timezone-informati. html
My Issue is, on the splunk web server, when I'm searching data, the Time column displayed GMT + 7, is not match with the raw data. On the raw data its --> 2018 Apr 10 15:42:03:735 GMT +0700 Test22, but on time column it was displayed 4/10/18 10:42:03.735 PM, it was not right. And I still cannot solve it out.
... View more