Getting Data In

Change timezone on Splunk Cloud

will_paxata
Explorer

My company is using Splunk Cloud and is located in the Pacific Time Zone. All of our log events include timezone offset in the format of YYYY-MM-dd HH:mm:ss.SSS 'GMT'Z.

For example, a log line could begin like so: "2015-05-13 10:44:23.956 GMT-0700". That log event is treated as UTC time (5/13/15 5:44:23.956 PM) for purposes of Splunk queries.

Is there a way to configure my Splunk account to execute queries, reports, and alerts in PST? That would actually be a big step in usability for my team.

Thanks in advance.

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings > Users and Authentication > Access controls > Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Excellent question, since in Splunk Enterprise you configure time zone settings by editing the props.conf file. You can set a user time zone using the Splunk Web UI: navigate to Settings > Users and Authentication > Access controls > Users. This will enable users to see search results in their own time zone, although it won't change the time zone of the event data.

will_paxata
Explorer

Excellent! Thanks for pointing that out. If you repost as an answer instead of a comment, I can accept your answer.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Thanks, glad that was helpful!

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...