<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135619#M27927</link>
    <description>&lt;P&gt;One thought, maybe adjusting timezone for your user through the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/SearchTutorial/NavigatingSplunk#User_menu"&gt;User Menu&lt;/A&gt; would help get you what you need? &lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2015 12:34:35 GMT</pubDate>
    <dc:creator>acharlieh</dc:creator>
    <dc:date>2015-06-04T12:34:35Z</dc:date>
    <item>
      <title>How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135618#M27926</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;I have an issue with time zones where my analysis system (Splunk Free) is in the Australian Eastern time zone and I am trying to analyze data which was captured in the Central European time zone. I checked the data imported and I have the right times on the data once I tell Splunk it originates in Europe. I see my times in the data.&lt;/P&gt;

&lt;P&gt;What I am doing is averaging the data over 24 hours. So when I say '15-May', I would like this to be 15 May in Europe, not Australia. I can't seem to figure out what I need to configure in Splunk to 'fool' it that I am analyzing in Europe. Do I need to change locale on my system?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Stan&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 11:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135618#M27926</guid>
      <dc:creator>brutecat</dc:creator>
      <dc:date>2015-06-04T11:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135619#M27927</link>
      <description>&lt;P&gt;One thought, maybe adjusting timezone for your user through the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/SearchTutorial/NavigatingSplunk#User_menu"&gt;User Menu&lt;/A&gt; would help get you what you need? &lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 12:34:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135619#M27927</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-06-04T12:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135620#M27928</link>
      <description>&lt;P&gt;Splunk presents times you, the user, as you tell it to through your users settings.  Go to &lt;CODE&gt;"Your User Name"&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Edit Account&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Time Zone&lt;/CODE&gt; and set this to the appropriate value and Splunk will automatically normalize both the &lt;CODE&gt;timepicker&lt;/CODE&gt; and all the results as they are presented to you.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 13:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135620#M27928</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-04T13:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135621#M27929</link>
      <description>&lt;P&gt;Thanks for that. I am using Splunk Free and it does not have the ability to do that. I adjust the system locale to be in Europe and it seems to be better aligned.&lt;/P&gt;

&lt;P&gt;Thanks for the pointer.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 22:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135621#M27929</guid>
      <dc:creator>brutecat</dc:creator>
      <dc:date>2015-06-04T22:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135622#M27930</link>
      <description>&lt;P&gt;acharlieh, I can't do this on Splunk Free. I should point this out to Splunk as a deficiency. Thanks anyway.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 22:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135622#M27930</guid>
      <dc:creator>brutecat</dc:creator>
      <dc:date>2015-06-04T22:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135623#M27931</link>
      <description>&lt;P&gt;I actually found the admin user (which is the only user in Splunk Free) configuration file:&lt;/P&gt;

&lt;P&gt;user-prefs.conf&lt;/P&gt;

&lt;P&gt;which looks like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[general]
appOrder = search
default_namespace = launcher
display.page.home.dashboardId = /servicesNS/nobody/simple_xml_examples/data/ui/views/linear_fits
showWhatsNew = 1
eai_app_only = False
eai_results_per_page = 25
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Perhaps I could make an entry there? Would someone make a temporary time zone change for a user and tell me what the key might be. The location of the file is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\Splunk\etc\users\admin\user-prefs\local
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Stan&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 22:42:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135623#M27931</guid>
      <dc:creator>brutecat</dc:creator>
      <dc:date>2015-06-04T22:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135624#M27932</link>
      <description>&lt;P&gt;This is what I found in mind:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[general]
eai_app_only = False
eai_results_per_page = 25
tz = America/Los_Angeles
restart_background_jobs = 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 08 Jun 2015 20:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135624#M27932</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-08T20:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135625#M27933</link>
      <description>&lt;P&gt;Hi Woodcock,&lt;/P&gt;

&lt;P&gt;Thanks for that. I tried it but it seems to make no difference. I need to set my system locale to the the target Central European Time. Perhaps this is a hidden limitation in the free version(?)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 20:48:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135625#M27933</guid>
      <dc:creator>brutecat</dc:creator>
      <dc:date>2015-06-08T20:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk so I can accurately analyze data captured in the Central European timezone?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135626#M27934</link>
      <description>&lt;P&gt;Only Splunk can say for sure; I am sorry that I cannot help you more.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 21:00:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-so-I-can-accurately-analyze-data/m-p/135626#M27934</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-08T21:00:00Z</dc:date>
    </item>
  </channel>
</rss>

