The field time_ISO is extracted but the _time
field was converted to UTC (EP time was CT).
Any time it sees in the raw event, EP converts it to UTC
Lookin for a way to tell EP to use the extracted time as the indexing time and not automatically assume UTC?
location seems to be the feature that I am looking for but its not an exposed configuration in the syslog receiver