Getting Data In

How to display data as a timeline in a table with correct timezone?

xploresplunk
New Member

I want to display my data as a timeline in a table. However, I noticed that the information that I'm analyzing has a timestamp that corresponds to a different timezone. I want to be able to display the time in my current timezone, which is US/Central. Is there a shortcut to modify the time? I thought about just subtracting the hours, but I don't know how to take into account when it is daylight saving time.

0 Karma

woodcock
Esteemed Legend

Go to <Your Name> -> Preferences -> Time zone and set it to whatever you like.

0 Karma

xploresplunk
New Member

Times still don't match. Is there another way to change the time through the search?

0 Karma

woodcock
Esteemed Legend

You are looking at the wrong thing. The raw text of the event will not change but notice that there are 3 fields in your search results: i, Time, and Event. The one that adjusts is Time.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...