List of questions
Related questions
Question 22 - SPLK-1005 discussion
The following Apache access log is being ingested into Splunk via a monitor input:
How does Splunk determine the time zone for this event?
A.
The value of the TZ attribute in props. cont for the a :ces3_ccwbined sourcetype.
B.
The value of the TZ attribute in props, conf for the my.webserver.example host.
C.
The time zone of the Heavy/Intermediate Forwarder with the monitor input.
D.
The time zone indicator in the raw event data.
Your answer:
0 comments
Sorted by
Leave a comment first