Splunk Search

What is the best way to compensate the hour shift as the daylight savings time comes and goes yearly?

jcorcoran508
Path Finder

I have this request to build a report

 

7am - 1900 Monday-Friday  CST

Sat 7am - noon   CST

 

Splunk is running on UTC - depending on the season the daylight savings 1 hour shift is 6hours or 5hours.

what is the best way to compensate the hour shift as the daylight savings time comes and goes yearly ?

Labels (6)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What do you mean by compensate?

Splunk store event timestamps in UTC, but these timestamps come from splunk's interpretation of the data in the events, which may or may not already be UTC or they could be local time and may or may not have timezone information to help splunk determine how to convert to UTC - is this where you want to "compensate" for daylight saving adjustments?

Splunk often displays times in local format, which takes daylight saving adjustments into account - is this where you want to "compensate" for daylight saving adjustments?

Please expand on your usecase - what is it you are trying to do?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...