Using SPLUNK 6.2.1 - How do I display all my date/times using the 24-hour clock? I want to keep the US Local for the date, but have the time show as 17:33;33 instead of 5:33:33.
I have seen some posts for version 4.1.1, but have not seen answers for the more recent versions.
No side-effects! In the actual indexes, Splunk stores all timestamps in Linux epoch time, with a timezone of UTC.
When Splunk displays times, it takes into account the user's timezone setting and the browser setting.