Splunk Search

How to fix timechart issue with dates involved in between a daylight savings time change?

csepulveda
New Member

Hi guys, we have a problem when we try to use timecharts that involve dates having in between a daylight saving time change.

If I change my timezone to GMT in account preferences, the timecharts query works fine, but if I do a span=1d it shows September 6 twice and doesn't show September 7.

If i change my timezone to GMT-4 Santiago, the query fails showing NaN numbers.

The query is

: sourcetype=varnish
account_id="50aa2711a6884125020019f1"
| timechart span=1d
distinct_count(customer_id)

All our logs has time fields on UTC.

any ideas?

Thanks!.

Tags (3)
0 Karma

aweitzman
Motivator

You might be running into this problem:

http://answers.splunk.com/answers/155320/why-is-the-search-app-time-range-picker-defaulting-to-2001-...

There's something magic about September 6, based on the comments in that thread.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...