Dashboards & Visualizations

Can you help us change the time zone in preferences page for a dashboard?

siva_cg
Path Finder

Hi

We have a Splunk environment with clustered indexers and a distributed search head running on the 7.1.3 version. All servers are in Belgium time zone (CET).

As we have users across the globe, we decided to use GMT as user time zone in the preferences page. Using this setting, when we select a time range in a dashboard panel, it is showing according to CET time zone rather than GMT time zone.

For example: If we select time range as earliest=31/10/2018 00:00:00 and latest=31/10/2018 10:00:00, then the graph is showing from earliest=30/10/2018 23:00:00 and latest=31/10/2018 09:00:00.

Also, this behavior is being observed only in dashboards but not for ad-hoc searches. Could you please help me to understand this pattern? Thanks in advance.

0 Karma

ivanreis
Builder

My suggestion is to create an app and add the user-prefs.conf the stanza below. Make sure the users that is assigned to the particular role should see the GMT time zone. Maybe you should create a new role and assign all the users that should have to see the GMT time to this role and add the stanza below.

[role_user]
tz = GMT

https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/User-prefsconf#user-prefs.conf.example

0 Karma

FrankVl
Ultra Champion

Are you hardcoding that timerange in the search behind the dashboard, or are you using the timepicker? And what user is used to execute the search behind the dashboard? Is that the end user, or are the searches ran on behalf of some other user (with other timezone preference)?

0 Karma

siva_cg
Path Finder

Hi @FrankVI,

we are using timepicker and search is being run by end user.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...