Dashboards & Visualizations

How to change UST timezone to PST time?

karthi2809
Builder

In my splunk dashboard i have table with time stamp of UST time .But my team is working in multiple timezone .So they want me to make default PST timezone in dashboard.How can we acheive this in splunk dashboard?

Labels (3)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hello! The key point is that Splunk stores all data in UTC, but displays it based on user preferences. This approach allows for flexibility without changing the actual data or dashboard configuration.

Here's an example to illustrate:

Let's say you have team members in New York (EST) and San Francisco (PST). An event occurs at 2:00 PM PST.

  1. The event is stored in Splunk as 10:00 PM UTC.
  2. The San Francisco team member (with PST preference) sees it as 2:00 PM.
  3. The New York team member (with EST preference) sees it as 5:00 PM.

Both are looking at the same data, but it's displayed in their local time.

To achieve this:

  1. Ensure correct timestamp configuration on data sources.
  2. Each user sets their preferred timezone in Splunk settings.

This method maintains data consistency while accommodating different timezones without modifying dashboards.

Please Upvote if this is Helpful.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...