Splunk Search

Do I need to restart Splunk after a daylight savings change?

Jason
Motivator

I'm looking at a client system right now that has the following:

  • the event has a timestamp of 18:00:00
  • the Splunk extrapolated time (in gray next to it on flashtimeline) of 18:00:00
  • the flash histogram above it (zoomed into a one-minute time interval) says 19:00:00

Does this just mean that daylight savings time has occurred and the splunkd hasn't yet been restarted?

Tags (3)
0 Karma

russellliss
Path Finder

I found that changing your timezone, and researching updates the extrapolated time, but I needed to logoff to have the histogram update to the correct time.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...