Hi all,
I am trying to change the timeset of the forwarders however it it not working.
As indicated in the URL (http://docs.splunk.com/Documentation/Splunk/latest/Data/Applytimezoneoffsetstotimestamps), I have already included the below property in the files:
/opt/splunk/etc/system/local/props.conf
/opt/splunk/etc/apps/"APPS"/default/props.conf
[sourcetype name]
TZ = America/Sao_Paulo
And after reset the splunk, i am still seeing the "_time" in UTC.
I already tried this property using host and source.
What else I need to do to reflect the timezone?
Thanks and regards,
Danillo Pavan
↧