I have a Splunk user in a Romanian timezone their search returns the events, let's say from midnight this day + one day. Another user in an England timezone also searches from midnight +one day, but it returns different results because of the timezone. I also use earliest=27/11/2016/0:0:0
and latest=29/11/2016/0:0:0
Anyone have any idea how to configure from query both timezones in order to receive same results?
Making sure I understand:
Let's say you have a log indexed at 10:00 UTC. You want users in say, timezones UTC-1 and UTC+3, to use the same time specifier in their search of 10:00 and get the same results?
Off hand, I'd say your best bet here is to have the users set their timezone context in Splunk to the same time zone.