Hi all,
I have found all schedule searches are running on EST instead of CET timezone, if i go and props.conf in /system/local
the Timezone showing TZ=UST .
could you please help me how to set CET time zone instead of EST.
Scheduled jobs run using the time zone of the user who scheduled the job. This can lead to great debugging confusion. I strongly urge my users to use UTC which is what all our logs use.
Identify owner of the scheduled searches in Settings » Searches, Reports, and Alerts.
Then check timezone set to the owner(s) in Settings » Access Control » Users. Click on user name to see it's settings. Change time zone to CET for user.
I have checked the Settings » Access Control » Users. the user timezone set to CET only. but the person run any schedule searches identified that EST time zone instead of CET
Check your systems (where splunk installed) time zone.
Actually for my user the Time zone showing EST but as a admin if try to open all the scheduled seatches about the user i can see CEST. i am not user why it's showing for the user differently. any guess why it's showing different for user how to resolve it .
Sorry TZ=UTC small correction.
What time zone is selected in your account's Splunk preferences?
I have checked the splunkd.log , all are running on CEST timezone on that particular host.
Your personal time zone preference will not be found in splunkd.log. Click on your name then select Preferences.
i am i have i have found CEST /CET in splunkd.log but if e run schedule searches related to one particular user , the searches are running in EST timezone instead of CET.
Even i have verified the user Settings » Access Control » Users , the timezone set to CET only . iam not sure where is the problem.