Splunk Search

Why is _time showing in 12 hr format in the following graph?

svijay30
Engager

alt text

For some reason, my column graph is showing the time in a 12hr (AM or PM) format, which I do not want.
The same query is being used for the statistics table, which is showing in a 24hr format.

Strangely, a user was able to see both graph and statistics in 24hrs format, But except for him, all other users could see the graph in a 12hr format.

please advise where to change this to get every thing(_time) in 24hr format.

1 Solution

FrankVl
Ultra Champion

Just tested a simple timechart in Splunk 7.2 and indeed, when locale is set to en-US, it shows 12h format in the graph x-axis (and also in the event view), but it is indeed showing in 24h format in the table below the graph (and in the Statistics view).

Anyway: if you want it to be 24h everywhere, just ensure your locale is set to en-GB, either by changing browser settings, or by changing the url in the address bar.

Might be worth checking with Splunk Support if this is by design, or a bug.

View solution in original post

FrankVl
Ultra Champion

Just tested a simple timechart in Splunk 7.2 and indeed, when locale is set to en-US, it shows 12h format in the graph x-axis (and also in the event view), but it is indeed showing in 24h format in the table below the graph (and in the Statistics view).

Anyway: if you want it to be 24h everywhere, just ensure your locale is set to en-GB, either by changing browser settings, or by changing the url in the address bar.

Might be worth checking with Splunk Support if this is by design, or a bug.

FrankVl
Ultra Champion

That's odd. The automagic display formatting of _time is governed by your browser's locale. For example en-US shows in 12h, en-GB shows in 24h. Having it displayed in 2 different formats for the same user is a bit weird.

What Splunk version is this?

Any chance you could share the specific search behind this graph and table? To double check that is not doing anything weird?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...