<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert to PST Time in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22899#M3593</link>
    <description>&lt;P&gt;Yes, I did this and nothing changes.&lt;BR /&gt;
[host::hostname]&lt;BR /&gt;
TZ = Etc./UTC&lt;/P&gt;

&lt;P&gt;My problem is not that logs are in different timezone than the Splunk server. My logs and Splunk server are in the same time zone. But my Splunk users are in PST.&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2013 23:46:39 GMT</pubDate>
    <dc:creator>lain179</dc:creator>
    <dc:date>2013-05-02T23:46:39Z</dc:date>
    <item>
      <title>Convert to PST Time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22897#M3591</link>
      <description>&lt;P&gt;Hello:&lt;/P&gt;

&lt;P&gt;My system log files are in GMT, as well as the Splunk forwarder and Splunk server. They are all in GMT (or UTC)&lt;/P&gt;

&lt;P&gt;However, my Splunk users are in PST time zone. So, I would like the splunk searches, reports and alerts to display the charts and tables in PST time. How can I accomplish that?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 22:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22897#M3591</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-05-02T22:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Convert to PST Time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22898#M3592</link>
      <description>&lt;P&gt;You can edit the time zone &lt;CODE&gt;TZ&lt;/CODE&gt; attribute in &lt;CODE&gt;props.conf&lt;/CODE&gt;. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/data/Applytimezoneoffsetstotimestamps"&gt;Specify time zones of timestamps&lt;/A&gt; in the Getting Data In manual.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 23:15:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22898#M3592</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-05-02T23:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Convert to PST Time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22899#M3593</link>
      <description>&lt;P&gt;Yes, I did this and nothing changes.&lt;BR /&gt;
[host::hostname]&lt;BR /&gt;
TZ = Etc./UTC&lt;/P&gt;

&lt;P&gt;My problem is not that logs are in different timezone than the Splunk server. My logs and Splunk server are in the same time zone. But my Splunk users are in PST.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 23:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22899#M3593</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-05-02T23:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Convert to PST Time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22900#M3594</link>
      <description>&lt;P&gt;Ah, sorry, I misunderstood. You can set each user's time zone in Manager, so they can see events in their own time zone. Manager &amp;gt; Access controls &amp;gt; Users.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 16:48:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22900#M3594</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-05-03T16:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Convert to PST Time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22901#M3595</link>
      <description>&lt;P&gt;We have hundreds of users imported from LDAP. Is there any way to make a mass tiemzone edit for all users? They are all set to "Default System TimeZone" --- may be I can change the default to PST? How do I do that? Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 21:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22901#M3595</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-05-08T21:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Convert to PST Time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22902#M3596</link>
      <description>&lt;P&gt;I see...I don't think there is any way to do a multiple user update like this within Splunk. You would have to write a script to update the tz setting in each user file, which is in $SPLUNK_HOME/etc/users/&lt;SOMEUSERID&gt;/user-prefs/local/user-prefs.conf.&lt;/SOMEUSERID&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 22:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Convert-to-PST-Time/m-p/22902#M3596</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-05-08T22:12:46Z</dc:date>
    </item>
  </channel>
</rss>

