Splunk Search

How do I configure timezone settings in Splunk so users in different timezones receive the same results?

ion1234
Engager

I have a Splunk user in a Romanian timezone their search returns the events, let's say from midnight this day + one day. Another user in an England timezone also searches from midnight +one day, but it returns different results because of the timezone. I also use earliest=27/11/2016/0:0:0 and latest=29/11/2016/0:0:0

Anyone have any idea how to configure from query both timezones in order to receive same results?

jlanders
Path Finder

Making sure I understand:

Let's say you have a log indexed at 10:00 UTC. You want users in say, timezones UTC-1 and UTC+3, to use the same time specifier in their search of 10:00 and get the same results?

Off hand, I'd say your best bet here is to have the users set their timezone context in Splunk to the same time zone.

0 Karma

jlanders
Path Finder
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...