Splunk Search

How to fix timechart issue with dates involved in between a daylight savings time change?

csepulveda
New Member

Hi guys, we have a problem when we try to use timecharts that involve dates having in between a daylight saving time change.

If I change my timezone to GMT in account preferences, the timecharts query works fine, but if I do a span=1d it shows September 6 twice and doesn't show September 7.

If i change my timezone to GMT-4 Santiago, the query fails showing NaN numbers.

The query is

: sourcetype=varnish
account_id="50aa2711a6884125020019f1"
| timechart span=1d
distinct_count(customer_id)

All our logs has time fields on UTC.

any ideas?

Thanks!.

Tags (3)
0 Karma

aweitzman
Motivator

You might be running into this problem:

http://answers.splunk.com/answers/155320/why-is-the-search-app-time-range-picker-defaulting-to-2001-...

There's something magic about September 6, based on the comments in that thread.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...