Hello Splunkers,
I have a scenario where I need to generate a report for last 6 month's data. In the query I have implemented timechart with a span of 1 month and the statistics generated should display data till 00:00 AM of the first day of the current month. But the issue is, the report statistics are correct (please refer reports2_ss ), but line graph is displaying data for previous month instead of the current month (please refer reports_ss) in which the data is ingested. I need all the data till 00:00 AM of the current month.
for example:-
Report is scheduled to run 00:00 AM on the 1st day of every month.! (i.e.it will run on 00:00 AM of 1st feb 2020)
I have ingested data on 20th of january.
But the report statistics are generated till 06:30 PM of 31st Dec. Displaying that data is ingested between 30th Nov to 6:30PM of 31st Dec.
Please find the screenshots attached for better understanding.
Please help me out with this issue!
What TZ does the user who created and scheduled the report have set in their Splunk prefs?
I am pretty certain (but not near a Splunk instance to check) that scheduled reports honour the users Time Zone preferences, not the systems.
The user who created the report has default system timezone set as their TZ in splunk. Still it is showing the report on last day of previous month at 6:30 PM. I want the results to be displayed till 1st of every month at 00:00 AM.
please provide your query and log samples.