Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is it possible to change the timezone of logs from a feed based on a field value?

$
0
0
Is there a way in the configuration of a feed (this is a pull from AWS) to look at a field value (state) and change the time to reflect when the event occurred? All the logs I currently get are in GMT, but the state field can set the event time if I can do this. I know I can do it in the search, but would like to have the feed properties reset the time instead. Thanks for any reply...

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>