Getting Data In

Change timezone on Splunk Cloud

will_paxata
Explorer

My company is using Splunk Cloud and is located in the Pacific Time Zone. All of our log events include timezone offset in the format of YYYY-MM-dd HH:mm:ss.SSS 'GMT'Z.

For example, a log line could begin like so: "2015-05-13 10:44:23.956 GMT-0700". That log event is treated as UTC time (5/13/15 5:44:23.956 PM) for purposes of Splunk queries.

Is there a way to configure my Splunk account to execute queries, reports, and alerts in PST? That would actually be a big step in usability for my team.

Thanks in advance.

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings > Users and Authentication > Access controls > Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings > Users and Authentication > Access controls > Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.

will_paxata
Explorer

Excellent! Thanks for pointing that out. If you repost as an answer instead of a comment, I can accept your answer.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Thanks, glad that was helpful!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...