Getting Data In

Custom time not working maybe locale issue

nigelowen
New Member

I set the custom time to June 14 11:48:00 -> June 14 11:48:05. I then click on search and the log info is shown but the search on the screen states "198 events from 11:48:00 AM to 11:48:05 AM on Sunday, June 13, 2010". I assume I need to set some sort of locale ? I am in New Zealand.

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This sounds like a bug to me.

0 Karma

parallaxed
Path Finder

Depending on the source of your data you need to set TZ appropriately, both on the input (props.conf), and in your environment ("export TZ=My/TimeZone")

http://en.wikipedia.org/wiki/List_of_zoneinfo_time_zones

Splunk will then search correctly with your given offsets, unless something extra-special is happening.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...