Splunk Search
Highlighted

Why is _time showing in 12 hr format in the following graph?

Engager

alt text

For some reason, my column graph is showing the time in a 12hr (AM or PM) format, which I do not want.
The same query is being used for the statistics table, which is showing in a 24hr format.

Strangely, a user was able to see both graph and statistics in 24hrs format, But except for him, all other users could see the graph in a 12hr format.

please advise where to change this to get every thing(_time) in 24hr format.

Highlighted

Re: Why is _time showing in 12 hr format in the following graph?

Ultra Champion

That's odd. The automagic display formatting of _time is governed by your browser's locale. For example en-US shows in 12h, en-GB shows in 24h. Having it displayed in 2 different formats for the same user is a bit weird.

What Splunk version is this?

Any chance you could share the specific search behind this graph and table? To double check that is not doing anything weird?

0 Karma
Highlighted

Re: Why is _time showing in 12 hr format in the following graph?

Ultra Champion

Just tested a simple timechart in Splunk 7.2 and indeed, when locale is set to en-US, it shows 12h format in the graph x-axis (and also in the event view), but it is indeed showing in 24h format in the table below the graph (and in the Statistics view).

Anyway: if you want it to be 24h everywhere, just ensure your locale is set to en-GB, either by changing browser settings, or by changing the url in the address bar.

Might be worth checking with Splunk Support if this is by design, or a bug.

View solution in original post