Dashboards & Visualizations

Change all user timezone

BrianLam
Engager

Hi, 

 

I would like to ask to how change all user timezone to Pacific time. I did some research and see people recommend to config this file - SPLUNK_HOME/etc/apps/user-prefs/local/user-prefs.conf. But from what I know, or at learst how my Splunk was set up. It's a Saas, they provided me a link to my domain and I start using it. I'm not quite sure where exactly is the mentioned file.

 

Thanks,

Brian 

Labels (1)
Tags (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "Saas" here? It's either a Splunk Enterprise instance (either administered by you or a third party) or a Splunk Cloud service subscription.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

What you are meaning with “change tz for all users”? If they are sitting in PT time zone and they are using “use system TZ settings” then it is already in PT time zone if their workstations/ laptops are correctly configured.

If you want to change that also for people which are not sitting in PT zone, then I ask why?

In internally splunk is storing all times as UTC. Then it shows times by users time zone or what they have set in their account preferences.

0 Karma

BrianLam
Engager

I created roles using SAML config then assign the role to user when they are created. I looked into all users and they don't have a default time zone set to their account. Yes they can set it through preference and I also can manually change it in Setting for all of the users but it's tedious to do one by one. I want to config it so that all the old and future users would have PT time zone automatically.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
If they haven’t set any time zone then it’s their workstation’s time zone. Is this tz wrong or what is the issue? I’m afraid that you are trying to solve an issue which doesn’t exists!
0 Karma

BrianLam
Engager

yes, the time zone is wrong, I check with a user, they're located in PT time zone but their default time zone is UTC.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
The Splunk’s TZ has set to UTC on browser and workstation has correct PT TZ? What SSO/idp you are using?
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...