Splunk Search

What is the best way to compensate the hour shift as the daylight savings time comes and goes yearly?

jcorcoran508
Path Finder

I have this request to build a report

 

7am - 1900 Monday-Friday  CST

Sat 7am - noon   CST

 

Splunk is running on UTC - depending on the season the daylight savings 1 hour shift is 6hours or 5hours.

what is the best way to compensate the hour shift as the daylight savings time comes and goes yearly ?

Labels (6)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What do you mean by compensate?

Splunk store event timestamps in UTC, but these timestamps come from splunk's interpretation of the data in the events, which may or may not already be UTC or they could be local time and may or may not have timezone information to help splunk determine how to convert to UTC - is this where you want to "compensate" for daylight saving adjustments?

Splunk often displays times in local format, which takes daylight saving adjustments into account - is this where you want to "compensate" for daylight saving adjustments?

Please expand on your usecase - what is it you are trying to do?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...