Hi,
I'm new to splunk and have just installed version 4.1.6. I am from Australia where we display the date as dd/mm/yyyy.
How do I set the date format so that everything is displayed in the format above? Through searching I can see answers for version 3 where [ui] settings need to be added to the literals.conf file but [ui] does not exist in the default literals.conf file for version 4?
You should only need to change the URL you use to access Splunk. This might help: http://answers.splunk.com/questions/525/how-can-i-change-the-time-format-in-splunk-web/526#526
The link provided in my response has one option. There is another posted here: http://answers.splunk.com/questions/10265/change-default-web-ui-locale
Apologies, it does appear to work for the date in searches. The date on the summary page under Global summary is still in the wrong format. Not a big deal. How do I set en-GB as the default? We have a friendly DNS entry for Splunk. Would prefer not to make users change this everytime they type it in...
Thanks for your response. unfortunately that only seems to change the way the time is displayed. It has no bearing on the date.