<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I change my Alert TZ? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449304#M11538</link>
    <description>&lt;P&gt;Yes, I have set the time preference for the user that the Alert is run as ... but I still get GMT instead of my adjusted TZ. I have tried different users and have the same thing. I am running 7.3&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 00:47:28 GMT</pubDate>
    <dc:creator>kmower</dc:creator>
    <dc:date>2019-07-02T00:47:28Z</dc:date>
    <item>
      <title>How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449291#M11525</link>
      <description>&lt;P&gt;I have set up some alerts and I noticed that when I include 'Trigger Time' it is sent as GMT. Now I want it to be the local (Australia Eastern Standard Time). I have adjusted for iis logs by putting the iis and ms:iis:auto sourcetypes in etc\system\local\props.conf ... but since an 'Alert' is not a sourcetype and is not 'indexed' per se - how do I designate the time zone for the Alert 'Trigger Time' ? Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 01:54:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449291#M11525</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-06-26T01:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449292#M11526</link>
      <description>&lt;P&gt;Hi @kmower ,&lt;BR /&gt;
The time settings your are talking about are dependent upon the current users' preferences in the Splunk UI.  Check under your user ID and preferences in the upper right of the Splunk UI.  The default is to use the system (search head) time zone settings, which are probably GMT.  You can change it to AEST, and then go back to your alerts and configure the scheduled times and trigger times for your AEST time settings.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 02:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449292#M11526</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-06-26T02:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449293#M11527</link>
      <description>&lt;P&gt;OK, great thanks. I will try that out. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:06:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449293#M11527</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-06-26T03:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449294#M11528</link>
      <description>&lt;P&gt;OK, I am the Admin for our on prem instance ... and my time zone was set correctly in preferences... but the Alert 'Trigger Time' in the email is GMT.  Is there a .conf file where I can make the change for Alerts? Other than that I can just untick 'Triggered Time' but I would prefer to have 'Trigger Time' instead of relying on the email time. Thanks again.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:09:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449294#M11528</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-06-26T03:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449295#M11529</link>
      <description>&lt;P&gt;Can you provide a screenshot of what you're referring to?  The time settings should all be relative to your preferred time zone settings.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449295#M11529</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-06-26T03:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449296#M11530</link>
      <description>&lt;P&gt;Aww Snap ... not enough Karma for attachments &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; happy to send wherever ... &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449296#M11530</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-06-26T03:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449297#M11531</link>
      <description>&lt;P&gt;Anyway, I am in GMT+10, and that is set in my user preferences. I had an Alert generated at 12:55pm my time (half an hour ago) and the 'Triggered Time' showed as 03:55:02 T-1 which is GMT ... 12:55pm - 10 hours = 3:55am&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449297#M11531</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-06-26T03:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449298#M11532</link>
      <description>&lt;P&gt;joshua(dot)nudell(at)concanon(dot)com&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449298#M11532</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-06-26T03:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449299#M11533</link>
      <description>&lt;P&gt;Forgot to mention, it will run as the timezone of the owner of the alert.  I've checked, and it definitely uses the timezone settings from the user that has ownership to display the trigger time.  I validated on my instance with a dummy alert, and the trigger time changes as I changed my user timezone preferences.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 03:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449299#M11533</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-06-26T03:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449300#M11534</link>
      <description>&lt;P&gt;Hmmm. Well, I definitely created it as the Admin user (me) and the Admin user's prefs are in GMT+10 , but the 'Trigger Time' is getting sent as GMT. I am running 7.3 ... perhaps it is a bug? Weird. I set the local time a long time ago.... the 'T-1' added on the back of the Trigger Time makes me wonder if there are other 'times' such as T-2, T-3, etc. Do you you know why that 'T-1' is appended? &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 04:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449300#M11534</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-06-26T04:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449301#M11535</link>
      <description>&lt;P&gt;Why don't you just add an eval function to your alert query and calculate the time difference into a new key or overwrite the trigger time key?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 21:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449301#M11535</guid>
      <dc:creator>dbroggy</dc:creator>
      <dc:date>2019-07-01T21:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449302#M11536</link>
      <description>&lt;P&gt;Go to &lt;CODE&gt;&amp;lt;Your Name&amp;gt;&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Preferences&lt;/CODE&gt; -&amp;gt; &lt;CODE&gt;Time zone&lt;/CODE&gt; and set it as you like.  Then be sure that the saved search runs AS THAT USER!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 22:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449302#M11536</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-01T22:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449303#M11537</link>
      <description>&lt;P&gt;Good idea. How would I overwrite (or get a handle on) the trigger time key? Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 00:46:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449303#M11537</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-07-02T00:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449304#M11538</link>
      <description>&lt;P&gt;Yes, I have set the time preference for the user that the Alert is run as ... but I still get GMT instead of my adjusted TZ. I have tried different users and have the same thing. I am running 7.3&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 00:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449304#M11538</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-07-02T00:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449305#M11539</link>
      <description>&lt;P&gt;This absolutely a bug.  If you have set the search to run &lt;CODE&gt;As owner&lt;/CODE&gt; and the owner has those settings, then you need to open a case.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 01:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449305#M11539</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-02T01:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449306#M11540</link>
      <description>&lt;P&gt;Right. I'll jump on and lodge it now. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 01:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449306#M11540</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-07-02T01:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change my Alert TZ?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449307#M11541</link>
      <description>&lt;P&gt;I'm not sure what your alert is looking at but normally the trigger time would be the same time as the last event associated with your alert. I appreciate whatever is actually set as the trigger time information might not be stored in your event but generated via backend python. eg. &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/293978/how-to-change-the-alert-email-trigger-time-format.html"&gt;https://answers.splunk.com/answers/293978/how-to-change-the-alert-email-trigger-time-format.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 02:51:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-change-my-Alert-TZ/m-p/449307#M11541</guid>
      <dc:creator>dbroggy</dc:creator>
      <dc:date>2019-07-02T02:51:17Z</dc:date>
    </item>
  </channel>
</rss>

