Hey All,
Recently, I have migrated data from some indexes from a distributed Splunk instance to clustered Splunk instance using bucket migration approach.
After the indexes data migration , I can see the same data and event counts for each indexes in both the old and new instance for a specific time range set manually from the time range filter.
But, since the older instance is in EDT time zone and new instance is in UTC time zone, when I am comparing the dashboards for validation purpose which uses those indexes , I can see the count mismatch because of the time zone difference.
I tried changing the preference to same time zones in both the instances but its not working.
Can anyone please help and let me know how can this issue be resolved so that the dashboards can be validated without setting the time range manually every time.