Getting Data In

How to change time zone from EST to CET on schedule searches ?

90509
Engager

Hi all,

I have found all schedule searches are running on EST instead of CET timezone, if i go and props.conf in /system/local
the Timezone showing TZ=UST .

could you please help me how to set CET time zone instead of EST.

0 Karma

burwell
SplunkTrust
SplunkTrust

Scheduled jobs run using the time zone of the user who scheduled the job. This can lead to great debugging confusion. I strongly urge my users to use UTC which is what all our logs use.

manjunathmeti
Champion

Identify owner of the scheduled searches in Settings » Searches, Reports, and Alerts.

Then check timezone set to the owner(s) in Settings » Access Control » Users. Click on user name to see it's settings. Change time zone to CET for user.

0 Karma

90509
Engager

I have checked the Settings » Access Control » Users. the user timezone set to CET only. but the person run any schedule searches identified that EST time zone instead of CET

0 Karma

manjunathmeti
Champion

Check your systems (where splunk installed) time zone.

0 Karma

90509
Engager

Actually for my user the Time zone showing EST but as a admin if try to open all the scheduled seatches about the user i can see CEST. i am not user why it's showing for the user differently. any guess why it's showing different for user how to resolve it .

0 Karma

90509
Engager

Sorry TZ=UTC small correction.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What time zone is selected in your account's Splunk preferences?

---
If this reply helps you, Karma would be appreciated.
0 Karma

90509
Engager

I have checked the splunkd.log , all are running on CEST timezone on that particular host.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your personal time zone preference will not be found in splunkd.log. Click on your name then select Preferences.

---
If this reply helps you, Karma would be appreciated.
0 Karma

90509
Engager

i am i have i have found CEST /CET in splunkd.log but if e run schedule searches related to one particular user , the searches are running in EST timezone instead of CET.

Even i have verified the user Settings » Access Control » Users , the timezone set to CET only . iam not sure where is the problem.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...