List of questions
Related questions
Question 182 - SPLK-1003 discussion
A Universal Forwarder has the following active stanza in inputs . conf:
[monitor: //var/log]
disabled = O
host = 460352847
An event from this input has a timestamp of 10:55. What timezone will Splunk add to the event as part of indexing?
A.
Universal Coordinated Time.
B.
The timezone of the search head.
C.
The timezone of the indexer that indexed the event.
D.
The timezone of the forwarder.
Your answer:
0 comments
Sorted by
Leave a comment first