Dashboards & Visualizations

Why doesn't the time picker work properly at "appmgmt data"?

stardust927
Explorer

I downloaded "Application Management v2.0".

This is my query

index=appmgmt sourcetype=access_combined
| timechart count span=5m

And I set earleist time as "1525878000" and latest time as "now".

I expected the graph begins at 2018.05.10 00:00:00, but it doesn't

It came out like this

alt text

You can see it starts at 2018.5.09 16:00.

It makes me crazy, why time doesn't the picker work properly?

When I use "static table" format with same query it came out correctly

alt text

But when I make it with graph format, it draw wrong timezone..

Tags (2)

niketn
Legend

@stardust927, could this be due to your timezone setting as Splunk's logged in user?

http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureuserswithSplunkWeb

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

stardust927
Explorer

Well...I think timezone setting is correct, because when I use "static table" format with same query timezone came out correct.
But if I use graph format it came out weird... I added picture at my question.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...