Splunk Enterprise Security

Rules Time Zones

astatrial
Contributor

Hi All,

I need to build a rule that alerts for specific activity by specific user past working hours.

For example:

I want to alert when user "Dani" logs in to the computer not between 7:00 - 18:00.

The problem is that the user is not in the same time zone as me.

So login logs at 19:00 in my time zone can be actually at 14:00 in the other user time zone.

-  Does anyone know what is the time zone that the rules go by?

-  Is it set by the configuration of the user that the rule is running as? 

 

Thanks ! 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, the rules use the time zone of the user running the rule.

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Thanks for the fast reply.

 

If the time zone of the user is changed? Does it also changed for the rules?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...