Dear Splunk Professionals,
We have a requirement here to change/correct the TZ settings as few sourcetype are having different TZ and others have different. We have configured TZ wrt [my_sourcetype] in indexer's props.conf.
Bu doing this the new event is coming with proper Timestamp TZ now. But the old already indexed data is with old Timezone only.
So wanted to check if any of you have any solution for this?
Thanks,
↧