Dashboards & Visualizations

Time range picker is not extracting the right time.

synastraa
Path Finder

Hi all,

Am currently new to Splunk and I'm facing an issue regarding the time range picker pulling up results that are inaccurate.

As I have select the last 24 hours options for the time range picker, the results that are displayed were only till a certain timing and not the full 24 hours duration.
I have attached a screenshot of the data captured as well as the time I have run the search. As seen in the screenshot, the last data captured was 5.52pm 28/3/19, while my last indexed data was at 3am on 29/3/19. Could anyone help me out on this? There seems to be a 8 hour difference in my time range picker when filtering the data. Thanks!
imgur.com/a/5hYT6Fb ( Was unable to provide the link as I don't have enough points..)

Best Regards,
Aloysius

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

You need to set <Your Name/UserID> -> Preferences -> Time zone to your local TZ and it should do what you expect.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You need to set <Your Name/UserID> -> Preferences -> Time zone to your local TZ and it should do what you expect.

0 Karma

niketn
Legend

@synastraa you should be able to add image using the image <img> button or shortcut Ctrl+G on Splunk Answers.

alt text

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

renjith_nair
Legend

@synastraa,
Is your user timezone setting and the timezone in the events are same ?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

synastraa
Path Finder

Hi renjith,

How would i go about on checking the timezone for my user setting and event settings. Thanks!

Best Regards,
Aloysius

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...