Getting Data In

Change timezone on Splunk Cloud

will_paxata
Explorer

My company is using Splunk Cloud and is located in the Pacific Time Zone. All of our log events include timezone offset in the format of YYYY-MM-dd HH:mm:ss.SSS 'GMT'Z.

For example, a log line could begin like so: "2015-05-13 10:44:23.956 GMT-0700". That log event is treated as UTC time (5/13/15 5:44:23.956 PM) for purposes of Splunk queries.

Is there a way to configure my Splunk account to execute queries, reports, and alerts in PST? That would actually be a big step in usability for my team.

Thanks in advance.

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings > Users and Authentication > Access controls > Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings > Users and Authentication > Access controls > Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.

will_paxata
Explorer

Excellent! Thanks for pointing that out. If you repost as an answer instead of a comment, I can accept your answer.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Thanks, glad that was helpful!

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...