<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change timezone on Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109711#M23054</link>
    <description>&lt;P&gt;Excellent! Thanks for pointing that out. If you repost as an answer instead of a comment, I can accept your answer.&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2015 20:19:41 GMT</pubDate>
    <dc:creator>will_paxata</dc:creator>
    <dc:date>2015-05-13T20:19:41Z</dc:date>
    <item>
      <title>Change timezone on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109709#M23052</link>
      <description>&lt;P&gt;My company is using Splunk Cloud and is located in the Pacific Time Zone. All of our log events include timezone offset in the format of YYYY-MM-dd HH:mm:ss.SSS 'GMT'Z.&lt;/P&gt;

&lt;P&gt;For example, a log line could begin like so: "2015-05-13 10:44:23.956 GMT-0700". That log event is treated as UTC time (5/13/15 5:44:23.956 PM) for purposes of Splunk queries.&lt;/P&gt;

&lt;P&gt;Is there a way to configure my Splunk account to execute queries, reports, and alerts in PST? That would actually be a big step in usability for my team.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 18:06:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109709#M23052</guid>
      <dc:creator>will_paxata</dc:creator>
      <dc:date>2015-05-13T18:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change timezone on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109710#M23053</link>
      <description>&lt;P&gt;Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings &amp;gt; Users and Authentication &amp;gt; Access controls &amp;gt; Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 19:00:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109710#M23053</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-05-13T19:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Change timezone on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109711#M23054</link>
      <description>&lt;P&gt;Excellent! Thanks for pointing that out. If you repost as an answer instead of a comment, I can accept your answer.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 20:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109711#M23054</guid>
      <dc:creator>will_paxata</dc:creator>
      <dc:date>2015-05-13T20:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Change timezone on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109712#M23055</link>
      <description>&lt;P&gt;Thanks, glad that was helpful!&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 20:21:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-timezone-on-Splunk-Cloud/m-p/109712#M23055</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-05-13T20:21:33Z</dc:date>
    </item>
  </channel>
</rss>

