Splunk Search

bin/timechart and timezones- Is there Splunk Documentation about their behaviour?

PickleRick
SplunkTrust
SplunkTrust

Binning/timecharting seems quite straightforward regarding time... unless you want to span day+ ranges.

From experience I might say that if you bin or timechart with span of a day or more, the value of _time gets snapped to midnight in user's timezone.

That's what experience shows.

But the question is (because I can't find any) is there an official Splunk documentation stating that this is the designed behaviour?

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...