Getting Data In

Time input is not selecting the proper time

kishan2356
Explorer

Hi

I have a dashboard where I use a time input. If I go to Between Date Times and say I select dates of 11/12/2019 08:00.00.000 and 11/12/2019 10:00.00.000, what happens is that the input displays data from 07:00.00.000 to 09:00.00.000, which is 1 hour off. Is there a way to fix it so that the time input only pulls data for exactly the time selected? Thanks. If more info is needed please let me know.

Tags (2)
0 Karma

wmyersas
Builder

This sounds like a time zone issue - most likely your server is running an hour behind you (either because DST just ended, or because it's in a different time zone).

0 Karma

kishan2356
Explorer

Hey wmyersas

Thank you for your reply but the problem we run into is that the search works sometimes and not other times. We do not think it is a time zone issue. If its a timezone issue it would not work at anytime.

0 Karma

wmyersas
Builder

What do you mean "sometimes and not other times"?

Who is running the search? What are their personal preferences set to for timezone? What timezone is the server running on?

99% chance this is a timezone-related problem.

kishan2356
Explorer

Say I enter 11/12/2019 8:00.000 to 10:00.000, all the data between these 2 times is displayed which is fine, but other times instead of displaying data between 8 and 10 it will display it from 7 to 9. The server is running on ET.

0 Karma

wmyersas
Builder

Best practice is to always run every server on UTC (since that will always match Unix epoch time)

What you're describing is a timezone issue

Either the data coming-in is off-by-1-hour

Or the user's timezone is off-by-1-hour

Or the server's time is off-by-1-hour

Or some random combination of the above

I've seen this countless times over the last dozen+ years - with maybe one exception in all that time, it was a time zone issue

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...