<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Dashboard Report Timezone Issue in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182699#M3958</link>
    <description>&lt;P&gt;I am seeing this issue with the Cisco Security App's Firewall Overview panel on the current version of Splunk Cloud as well. Is there an ETA on when this bug might be fixed? Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2016 13:06:40 GMT</pubDate>
    <dc:creator>delink</dc:creator>
    <dc:date>2016-03-30T13:06:40Z</dc:date>
    <item>
      <title>Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182693#M3952</link>
      <description>&lt;P&gt;All our servers (Splunk Indexer, Search Head and applications/universal forwarders) are in CST time zone.&lt;BR /&gt;
In Splunk UI, we have set the timezone as EST.&lt;BR /&gt;
Now, we have created a Splunk saved report for last 4 weeks (-4w@w to @w).&lt;BR /&gt;
Also, we have accelerated this report.&lt;BR /&gt;
When we run the report directly or via Open in Search, we get data 7/19/15 12:00:00.000 AM EST to 8/16/15 12:00:00.000 AM EST.&lt;BR /&gt;
Then, we added the report to existing multi-panel dashboard (not as inline search) but as direct report.&lt;BR /&gt;
However, now we get different values in panel.&lt;BR /&gt;
We found the reason, when we clicked on magnify glass "Open in Search" below in panel in dashboard.&lt;BR /&gt;
Reason, this panel runs between 7/19/15 01:00:00.000 AM EST to 8/16/15 01:00:00.000 AM EST&lt;BR /&gt;
Why would this occur?&lt;BR /&gt;
Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 11:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182693#M3952</guid>
      <dc:creator>477450</dc:creator>
      <dc:date>2015-08-21T11:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182694#M3953</link>
      <description>&lt;P&gt;Hi @477450,&lt;BR /&gt;
I'm a tech writer here at Splunk and I'd like to help with this. I am looking in to your question currently. I'm checking to see how time zones and/or the cron scheduling and handling for the report might be contributing to the issue you noticed. I'll report back with more information ASAP!&lt;/P&gt;

&lt;P&gt;Please feel free to post further questions or feedback here in the meantime.&lt;/P&gt;

&lt;P&gt;Best,&lt;BR /&gt;
@frobinson_splunk&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 16:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182694#M3953</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2015-08-21T16:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182695#M3954</link>
      <description>&lt;P&gt;Can I ask what version of the software you are using? Thanks for any details!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 16:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182695#M3954</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2015-08-21T16:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182696#M3955</link>
      <description>&lt;P&gt;Hi again, @477450,&lt;BR /&gt;
I wanted to let you know that our engineering team has identified this issue as a bug to fix. &lt;/P&gt;

&lt;P&gt;There may be a way to work around the problem for now, by adjusting settings in props.conf. In particular, take a look at the timezone configuration settings. It sounds like the report scheduling that you set up for 12 midnight EST is being interpreted as midnight CST, causing it to capture data one hour later, at 1am EST. Perhaps ensuring that this is set to EST would help?&lt;/P&gt;

&lt;P&gt;I'm not sure what version of the software you are using, but here is the props.conf spec file in our documentation:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Some other resources that you might find helpful:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/ApplyTimezoneOffsetsToTimeStamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/ApplyTimezoneOffsetsToTimeStamps&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/170285/one-dashboard-with-multiple-timezones.html"&gt;http://answers.splunk.com/answers/170285/one-dashboard-with-multiple-timezones.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 20:35:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182696#M3955</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2015-08-26T20:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182697#M3956</link>
      <description>&lt;P&gt;Hi thanks for the update&lt;BR /&gt;
we are using splunk version 6.2.0&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2015 09:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182697#M3956</guid>
      <dc:creator>477450</dc:creator>
      <dc:date>2015-08-28T09:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182698#M3957</link>
      <description>&lt;P&gt;Great--thank you for this info! I will pass it along to the engineer working on the bug. &lt;/P&gt;

&lt;P&gt;All the best,&lt;BR /&gt;
@frobinson_splunk&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2015 17:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182698#M3957</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2015-08-28T17:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Report Timezone Issue</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182699#M3958</link>
      <description>&lt;P&gt;I am seeing this issue with the Cisco Security App's Firewall Overview panel on the current version of Splunk Cloud as well. Is there an ETA on when this bug might be fixed? Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 13:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-Dashboard-Report-Timezone-Issue/m-p/182699#M3958</guid>
      <dc:creator>delink</dc:creator>
      <dc:date>2016-03-30T13:06:40Z</dc:date>
    </item>
  </channel>
</rss>

