Splunk Search

What is the best way to compensate the hour shift as the daylight savings time comes and goes yearly?

jcorcoran508
Path Finder

I have this request to build a report

 

7am - 1900 Monday-Friday  CST

Sat 7am - noon   CST

 

Splunk is running on UTC - depending on the season the daylight savings 1 hour shift is 6hours or 5hours.

what is the best way to compensate the hour shift as the daylight savings time comes and goes yearly ?

Labels (6)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What do you mean by compensate?

Splunk store event timestamps in UTC, but these timestamps come from splunk's interpretation of the data in the events, which may or may not already be UTC or they could be local time and may or may not have timezone information to help splunk determine how to convert to UTC - is this where you want to "compensate" for daylight saving adjustments?

Splunk often displays times in local format, which takes daylight saving adjustments into account - is this where you want to "compensate" for daylight saving adjustments?

Please expand on your usecase - what is it you are trying to do?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...