<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Real Time Search On Dashboard Time Zone in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101455#M21267</link>
    <description>&lt;P&gt;I have a dashboard that has 2 real time search counts and all the other panels are based on scheduled searches. The real time counts events on last 5 minutes. On the upper corner of each panel it displays the last time the search has been ran. It will say refreshed at hh:mm. The scheduled searches have the correct eastern time which is the time of the server and the logs. The real time search however is displaying my time zone (central time). Does that timestamp reflect the timezone of the browser or this being set somewhere? &lt;/P&gt;</description>
    <pubDate>Tue, 01 Nov 2011 00:17:07 GMT</pubDate>
    <dc:creator>edenael20</dc:creator>
    <dc:date>2011-11-01T00:17:07Z</dc:date>
    <item>
      <title>Real Time Search On Dashboard Time Zone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101455#M21267</link>
      <description>&lt;P&gt;I have a dashboard that has 2 real time search counts and all the other panels are based on scheduled searches. The real time counts events on last 5 minutes. On the upper corner of each panel it displays the last time the search has been ran. It will say refreshed at hh:mm. The scheduled searches have the correct eastern time which is the time of the server and the logs. The real time search however is displaying my time zone (central time). Does that timestamp reflect the timezone of the browser or this being set somewhere? &lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2011 00:17:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101455#M21267</guid>
      <dc:creator>edenael20</dc:creator>
      <dc:date>2011-11-01T00:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Search On Dashboard Time Zone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101456#M21268</link>
      <description>&lt;P&gt;There is a user/login-level setting that tells Splunk how to normalize timestamps when presenting data to each user.  It is in &lt;CODE&gt;Settings&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Edit Account&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Times zone&lt;/CODE&gt;.  This normalized time is shown only if you select &lt;CODE&gt;List&lt;/CODE&gt; or &lt;CODE&gt;Table&lt;/CODE&gt; (e.g. not &lt;CODE&gt;Raw&lt;/CODE&gt;) in the upper-left corner above the search results.  Doing so creates a &lt;CODE&gt;Time&lt;/CODE&gt; column next to the &lt;CODE&gt;Event&lt;/CODE&gt; column.  Do you see this?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 22:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101456#M21268</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-05T22:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Real Time Search On Dashboard Time Zone</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101457#M21269</link>
      <description>&lt;P&gt;Did this help?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 19:43:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Real-Time-Search-On-Dashboard-Time-Zone/m-p/101457#M21269</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-30T19:43:50Z</dc:date>
    </item>
  </channel>
</rss>

