Dashboards & Visualizations

Why doesn't the time picker work properly at "appmgmt data"?

stardust927
Explorer

I downloaded "Application Management v2.0".

This is my query

index=appmgmt sourcetype=access_combined
| timechart count span=5m

And I set earleist time as "1525878000" and latest time as "now".

I expected the graph begins at 2018.05.10 00:00:00, but it doesn't

It came out like this

alt text

You can see it starts at 2018.5.09 16:00.

It makes me crazy, why time doesn't the picker work properly?

When I use "static table" format with same query it came out correctly

alt text

But when I make it with graph format, it draw wrong timezone..

Tags (2)

niketn
Legend

@stardust927, could this be due to your timezone setting as Splunk's logged in user?

http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureuserswithSplunkWeb

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

stardust927
Explorer

Well...I think timezone setting is correct, because when I use "static table" format with same query timezone came out correct.
But if I use graph format it came out weird... I added picture at my question.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...