Hi,
I would like to ask to how change all user timezone to Pacific time. I did some research and see people recommend to config this file - SPLUNK_HOME/etc/apps/user-prefs/local/user-prefs.conf. But from what I know, or at learst how my Splunk was set up. It's a Saas, they provided me a link to my domain and I start using it. I'm not quite sure where exactly is the mentioned file.
Thanks,
Brian
What do you mean by "Saas" here? It's either a Splunk Enterprise instance (either administered by you or a third party) or a Splunk Cloud service subscription.
What you are meaning with “change tz for all users”? If they are sitting in PT time zone and they are using “use system TZ settings” then it is already in PT time zone if their workstations/ laptops are correctly configured.
If you want to change that also for people which are not sitting in PT zone, then I ask why?
In internally splunk is storing all times as UTC. Then it shows times by users time zone or what they have set in their account preferences.
I created roles using SAML config then assign the role to user when they are created. I looked into all users and they don't have a default time zone set to their account. Yes they can set it through preference and I also can manually change it in Setting for all of the users but it's tedious to do one by one. I want to config it so that all the old and future users would have PT time zone automatically.
yes, the time zone is wrong, I check with a user, they're located in PT time zone but their default time zone is UTC.