Dashboards & Visualizations

7.1 Dashboards not converting timepicker to timezone

Engager

I'm having two problems with splunk dashboards after I upgraded to 7.1.2. These only seem to occur when searching Date range or date-time range on dashboards. Making a custom search returns correclty. Relative time also works fine.

  1. Dashboards are using the searching computer's timezone as a base.
  2. Dashboards aren't converting the shared timepicker based on the timezone

I made 2 accounts, account A in my computer's local time (PST, -7 hrs since daylight savings) and account B in my splunk server's time (GMT).

  1. I make a timerange search since today (date range, since today) on my local computer. Account A returns from midnight (as expected) while account B returns from 7:00AM (PST as base time). in the URL the epoch time for both searches is the same, midnight PST epoch.
  2. I make a timerange search since today (date range, since today) on my splunk server. Account A returns from 5PM the previous day (GMT as base time) while account B returns from midnight (as expected). in the URL the epoch time for both searches is now midnight GMT epoch.

I've been looking into this for several days and I'm led to believe its a bug with splunk as I have another splunk host (unrelated to this instance, different data) which is still on 6.3 and the dashboard timeranges work correctly as expected. Help would be appreciated.

1 Solution

Splunk Employee
Splunk Employee

I was able to reproduce it easily. Looking internally I did find a bug which matches this description, SPL-157014. As soon as I have some information on that to share, I will update you. Thanks!

UPDATE

This is scheduled to be fixed in:

7.1.6 - SPL-163030
7.2.4 - SPL-163032

I am not aware of a work around.

Jacob
Sr. Technical Support Engineer

View solution in original post

Esteemed Legend

I have a workaround for this problem but first the background.

In my experience, this only happens when using - Default System Timezone -. Every user's Time zone preference setting starts out with a default value of - Default System Timezone -. This setting means that Splunk is supposed to use the OS's TZ setting that is running the Search Head. This works properly MOST of the time but DOES NOT work when you are inside of a Dashboard. In that case, it behaves as though the setting was set to (GMT) Greenwhich Mean Time. In our case the OS was set to (GMT-08:00) Pacific Time (US & Canada).

So the workaround is to use any other explicit setting for your Time zone preference setting.

0 Karma

Splunk Employee
Splunk Employee

I was able to reproduce it easily. Looking internally I did find a bug which matches this description, SPL-157014. As soon as I have some information on that to share, I will update you. Thanks!

UPDATE

This is scheduled to be fixed in:

7.1.6 - SPL-163030
7.2.4 - SPL-163032

I am not aware of a work around.

Jacob
Sr. Technical Support Engineer

View solution in original post

Esteemed Legend

See my answer for a workaround.

0 Karma

Path Finder

Do we have same issue in 7.1.4 version?

0 Karma

Splunk Employee
Splunk Employee

Yes, it is fixed in 7.1.6 and 7.2.4. 7.1.6 is currently available, 7.2.4 should be out in the next couple of weeks as far as I know.

Jacob
Sr. Technical Support Engineer

Path Finder

Thanks @jcrabb_splunk

0 Karma

Builder

Hi, I am hitting the same problem. do we have any update on this ? 7.2.3 version is out but don't think it has this fix. Thanks!!

0 Karma

Splunk Employee
Splunk Employee

I apologize, when I was out on holiday it looks like this got moved to 7.2.4. I have updated my answer and put in the bug #. They should be listed in the release notes once its available. If there are further changes I will update it once I am aware.

Jacob
Sr. Technical Support Engineer

Motivator

Hi

Do you have an ETA for 7.2.4 as i am also waiting on this fix before i upgrade

Cheers
Robert Lynch

0 Karma

Builder

@jcrabb_splunk : Thank you for update 🙂

0 Karma

Builder

@jcrabb_splunk - Is there a workaround available until the new version comes out?

When are the new versions scheduled for rollout?

0 Karma

Engager

Do you have any update? I also have the same issue with v7.2.0. Hope this will be fixed soon!

0 Karma

Splunk Employee
Splunk Employee

I wanted to let you know that the fix for this is currently scheduled for 7.1.5 and 7.2.3. That of course is subject to change but if testing goes well that is when you should see the fix. Thanks!

Jacob
Sr. Technical Support Engineer

Engager

@jcrabb,
Is there a way around to this problem ? I have a dashboard which has a timepicker. i save the time picked to a token and use it in different search. This dashboard is used from offices across globe so adjusting the time difference in epoch format is not an answer for me.

0 Karma

Splunk Employee
Splunk Employee

Development is actively working on the issue. I do not have a fix version or ETA at this time. As soon as I do, I will provide an update.

Jacob
Sr. Technical Support Engineer
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!