<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk's REST API to build aggregate reports, how do we view results in CDT with the correct time format? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-s-REST-API-to-build-aggregate-reports-how-do-we/m-p/229121#M44564</link>
    <description>&lt;P&gt;Log into the web user interface as the user you are using to pull the reports, and set the user's timezone to CDT.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2016 12:37:47 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-06-28T12:37:47Z</dc:date>
    <item>
      <title>Using Splunk's REST API to build aggregate reports, how do we view results in CDT with the correct time format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-s-REST-API-to-build-aggregate-reports-how-do-we/m-p/229120#M44563</link>
      <description>&lt;P&gt;We are using Splunk REST API (search/jobs/export) to build aggregated reports.&lt;/P&gt;

&lt;P&gt;Splunk server is in EDT, but we want to view the results in CDT. For that, we are using time filters in CDT as &lt;CODE&gt;earliest_time="2016-06-21T09:00:00-05:00" latest_time="2016-06-21T09:59:59-05:00"&lt;/CODE&gt;. The searches are running as per time range, but in the result, _time is populating in EDT with a different format like &lt;CODE&gt;2016-06-21 10:00:00.000 EDT&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Is there a way to get this _time as per time zone of applied time ranges or any other way to populate _time in a regular Splunk time format like &lt;CODE&gt;2016-06-20T13:00:59.878-04:00&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2016 19:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-s-REST-API-to-build-aggregate-reports-how-do-we/m-p/229120#M44563</guid>
      <dc:creator>kpkvarma</dc:creator>
      <dc:date>2016-06-25T19:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk's REST API to build aggregate reports, how do we view results in CDT with the correct time format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-s-REST-API-to-build-aggregate-reports-how-do-we/m-p/229121#M44564</link>
      <description>&lt;P&gt;Log into the web user interface as the user you are using to pull the reports, and set the user's timezone to CDT.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2016 12:37:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-s-REST-API-to-build-aggregate-reports-how-do-we/m-p/229121#M44564</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-06-28T12:37:47Z</dc:date>
    </item>
  </channel>
</rss>

