Dashboards & Visualizations

Why doesn't the time picker work properly at "appmgmt data"?

stardust927
Explorer

I downloaded "Application Management v2.0".

This is my query

index=appmgmt sourcetype=access_combined
| timechart count span=5m

And I set earleist time as "1525878000" and latest time as "now".

I expected the graph begins at 2018.05.10 00:00:00, but it doesn't

It came out like this

alt text

You can see it starts at 2018.5.09 16:00.

It makes me crazy, why time doesn't the picker work properly?

When I use "static table" format with same query it came out correctly

alt text

But when I make it with graph format, it draw wrong timezone..

Tags (2)

niketn
Legend

@stardust927, could this be due to your timezone setting as Splunk's logged in user?

http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureuserswithSplunkWeb

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

stardust927
Explorer

Well...I think timezone setting is correct, because when I use "static table" format with same query timezone came out correct.
But if I use graph format it came out weird... I added picture at my question.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...