Splunk Search

How to specify a timezone in a datamodel


Is there a way to specify a timezone in a datanmodel?

I have an eval field called date relying on Splunk's _time field but I want to ensure that it matches a specific timezone, rather than relying on the extracted _time of the log as its in UTC.

I want to have the timezone match Brisbane, Australia (+10)

Labels (2)
0 Karma


Timezone is applied at search time based on the users' settings. If none is set for the user Splunk will use the TZ of the server (default).

An upvote would be appreciated and Accept Solution if it helps!
0 Karma


This doesn't help in my instance because even though my timezone is set to mine, when doing a tstats datamodel the timezone is UTC no matter my settings

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...