I'm new to splunk and have just installed version 4.1.6. I am from Australia where we display the date as dd/mm/yyyy.
How do I set the date format so that everything is displayed in the format above? Through searching I can see answers for version 3 where [ui] settings need to be added to the literals.conf file but [ui] does not exist in the default literals.conf file for version 4?
Apologies, it does appear to work for the date in searches. The date on the summary page under Global summary is still in the wrong format. Not a big deal. How do I set en-GB as the default? We have a friendly DNS entry for Splunk. Would prefer not to make users change this everytime they type it in...