Getting Data In

How to use timezone in Multi-Timezone system?

dianbo_1
Path Finder

Hi,

There are several questions about timezone configuration.

  1. I know that splunk use the timezone information in raw event data first. But what kinds of timezone string can be used. In my test, CET, EDT, PST, GMT and GMT+0700 can be recognized, but Asia/Yerevan and Europe/Berlin can not be.

  2. How to set splunk's global timezone to a value that different from system's. For example, the timezone of server is GMT, then how to set splunk's global timezone to GMT+0100.

  3. If Splunk use system's timezone to get its time information, will it change correspondingly if the system's timezone is changed.

  4. How to display timezone information in the time column of the EventsViewer module in flashtimeline?

  5. How to specified timezone information when search in splunk web? We have a old syslog log analysis application which used to deal with log files in USA. Now we want to move all log datas to a splunk installed in a server in Deutschland. We specified timezone information in props.conf, so the times are changed to Deutsch time. But it is inconvenient for the users to change times by timezone when search in the splunk web (They should change the time string to Deutsch time before a search rather than search directly).

Thanks & Best Regards,

Dianbo

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
  1. Whatever zoneinfo names are on your system are valid, provided your time format captures them. On Windows, Splunk ships with a copy of the zoneinfo database.

  2. What do you mean by "Splunk global timezone" specifically? You can of course change the zone/locale for the Splunk user if you want it to run as if it were in another time zone.

  3. Yes.

  4. date_zone field contains the time zone offset from GMT, in minutes.

  5. There is currently no way to have Splunk Web display time zones in anything other than the Splunk server time. However, you could set up a Splunk search head in a different time zone and search back to an indexer in a different time zone. This will display all times in the search head time zone.

Simeon
Splunk Employee
Splunk Employee

You have too many questions lumped together. You should break them apart.

sideview
SplunkTrust
SplunkTrust

I think this is best split apart into a couple different questions here rather than lumped into a single large question.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...