Dashboards & Visualizations

7.1 Dashboards not converting timepicker to timezone

ryipea
Engager

I'm having two problems with splunk dashboards after I upgraded to 7.1.2. These only seem to occur when searching Date range or date-time range on dashboards. Making a custom search returns correclty. Relative time also works fine.

  1. Dashboards are using the searching computer's timezone as a base.
  2. Dashboards aren't converting the shared timepicker based on the timezone

I made 2 accounts, account A in my computer's local time (PST, -7 hrs since daylight savings) and account B in my splunk server's time (GMT).

  1. I make a timerange search since today (date range, since today) on my local computer. Account A returns from midnight (as expected) while account B returns from 7:00AM (PST as base time). in the URL the epoch time for both searches is the same, midnight PST epoch.
  2. I make a timerange search since today (date range, since today) on my splunk server. Account A returns from 5PM the previous day (GMT as base time) while account B returns from midnight (as expected). in the URL the epoch time for both searches is now midnight GMT epoch.

I've been looking into this for several days and I'm led to believe its a bug with splunk as I have another splunk host (unrelated to this instance, different data) which is still on 6.3 and the dashboard timeranges work correctly as expected. Help would be appreciated.

1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

I was able to reproduce it easily. Looking internally I did find a bug which matches this description, SPL-157014. As soon as I have some information on that to share, I will update you. Thanks!

UPDATE

This is scheduled to be fixed in:

7.1.6 - SPL-163030
7.2.4 - SPL-163032

I am not aware of a work around.

Jacob
Sr. Technical Support Engineer

View solution in original post

woodcock
Esteemed Legend

I have a workaround for this problem but first the background.

In my experience, this only happens when using - Default System Timezone -. Every user's Time zone preference setting starts out with a default value of - Default System Timezone -. This setting means that Splunk is supposed to use the OS's TZ setting that is running the Search Head. This works properly MOST of the time but DOES NOT work when you are inside of a Dashboard. In that case, it behaves as though the setting was set to (GMT) Greenwhich Mean Time. In our case the OS was set to (GMT-08:00) Pacific Time (US & Canada).

So the workaround is to use any other explicit setting for your Time zone preference setting.

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

I was able to reproduce it easily. Looking internally I did find a bug which matches this description, SPL-157014. As soon as I have some information on that to share, I will update you. Thanks!

UPDATE

This is scheduled to be fixed in:

7.1.6 - SPL-163030
7.2.4 - SPL-163032

I am not aware of a work around.

Jacob
Sr. Technical Support Engineer

woodcock
Esteemed Legend

See my answer for a workaround.

0 Karma

maniu1609
Path Finder

Do we have same issue in 7.1.4 version?

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

Yes, it is fixed in 7.1.6 and 7.2.4. 7.1.6 is currently available, 7.2.4 should be out in the next couple of weeks as far as I know.

Jacob
Sr. Technical Support Engineer

maniu1609
Path Finder

Thanks @jcrabb_splunk

0 Karma

AKG1_old1
Builder

Hi, I am hitting the same problem. do we have any update on this ? 7.2.3 version is out but don't think it has this fix. Thanks!!

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

I apologize, when I was out on holiday it looks like this got moved to 7.2.4. I have updated my answer and put in the bug #. They should be listed in the release notes once its available. If there are further changes I will update it once I am aware.

Jacob
Sr. Technical Support Engineer

robertlynch2020
Influencer

Hi

Do you have an ETA for 7.2.4 as i am also waiting on this fix before i upgrade

Cheers
Robert Lynch

0 Karma

AKG1_old1
Builder

@jcrabb_splunk : Thank you for update 🙂

0 Karma

dineshraj9
Builder

@jcrabb_splunk - Is there a workaround available until the new version comes out?

When are the new versions scheduled for rollout?

0 Karma

tdkeinoda
Engager

Do you have any update? I also have the same issue with v7.2.0. Hope this will be fixed soon!

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

I wanted to let you know that the fix for this is currently scheduled for 7.1.5 and 7.2.3. That of course is subject to change but if testing goes well that is when you should see the fix. Thanks!

Jacob
Sr. Technical Support Engineer

skomaravelli
Engager

@jcrabb,
Is there a way around to this problem ? I have a dashboard which has a timepicker. i save the time picked to a token and use it in different search. This dashboard is used from offices across globe so adjusting the time difference in epoch format is not an answer for me.

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

Development is actively working on the issue. I do not have a fix version or ETA at this time. As soon as I do, I will provide an update.

Jacob
Sr. Technical Support Engineer
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...