Dashboards & Visualizations

Why doesn't the time picker work properly at "appmgmt data"?

stardust927
Explorer

I downloaded "Application Management v2.0".

This is my query

index=appmgmt sourcetype=access_combined
| timechart count span=5m

And I set earleist time as "1525878000" and latest time as "now".

I expected the graph begins at 2018.05.10 00:00:00, but it doesn't

It came out like this

alt text

You can see it starts at 2018.5.09 16:00.

It makes me crazy, why time doesn't the picker work properly?

When I use "static table" format with same query it came out correctly

alt text

But when I make it with graph format, it draw wrong timezone..

Tags (2)

niketn
Legend

@stardust927, could this be due to your timezone setting as Splunk's logged in user?

http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureuserswithSplunkWeb

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

stardust927
Explorer

Well...I think timezone setting is correct, because when I use "static table" format with same query timezone came out correct.
But if I use graph format it came out weird... I added picture at my question.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...