Splunk Search

How do I configure timezone settings in Splunk so users in different timezones receive the same results?

ion1234
Engager

I have a Splunk user in a Romanian timezone their search returns the events, let's say from midnight this day + one day. Another user in an England timezone also searches from midnight +one day, but it returns different results because of the timezone. I also use earliest=27/11/2016/0:0:0 and latest=29/11/2016/0:0:0

Anyone have any idea how to configure from query both timezones in order to receive same results?

jlanders
Path Finder

Making sure I understand:

Let's say you have a log indexed at 10:00 UTC. You want users in say, timezones UTC-1 and UTC+3, to use the same time specifier in their search of 10:00 and get the same results?

Off hand, I'd say your best bet here is to have the users set their timezone context in Splunk to the same time zone.

0 Karma

jlanders
Path Finder
0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...