Getting Data In

Convert to PST Time

lain179
Communicator

Hello:

My system log files are in GMT, as well as the Splunk forwarder and Splunk server. They are all in GMT (or UTC)

However, my Splunk users are in PST time zone. So, I would like the splunk searches, reports and alerts to display the charts and tables in PST time. How can I accomplish that?

Thank you!

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

You can edit the time zone TZ attribute in props.conf. See Specify time zones of timestamps in the Getting Data In manual.

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

You can edit the time zone TZ attribute in props.conf. See Specify time zones of timestamps in the Getting Data In manual.

ChrisG
Splunk Employee
Splunk Employee

I see...I don't think there is any way to do a multiple user update like this within Splunk. You would have to write a script to update the tz setting in each user file, which is in $SPLUNK_HOME/etc/users//user-prefs/local/user-prefs.conf.

0 Karma

lain179
Communicator

We have hundreds of users imported from LDAP. Is there any way to make a mass tiemzone edit for all users? They are all set to "Default System TimeZone" --- may be I can change the default to PST? How do I do that? Thank you!

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Ah, sorry, I misunderstood. You can set each user's time zone in Manager, so they can see events in their own time zone. Manager > Access controls > Users.

0 Karma

lain179
Communicator

Yes, I did this and nothing changes.
[host::hostname]
TZ = Etc./UTC

My problem is not that logs are in different timezone than the Splunk server. My logs and Splunk server are in the same time zone. But my Splunk users are in PST.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...