Splunk Search

search strptime function using %Z and tz database time zones

kscher
Path Finder

Greetings,

Quoting from

https://docs.splunk.com/Documentation/Splunk/7.2.6/SearchReference/Commontimeformatvariables,

     Refer to the list of tz database time zones for all permissible time zone values. 

My question: Given a search statement such as

 

 

strptime(SLA." ".timeZone, "%H:%M %Z")

 

 

Does Splunk have any built-in time zone database that might require periodic updates as for instance, when a locale changes its standard to daylight saving dates, or does Splunk simply use the database that's baked into a lower layer of the stack?

 

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It depends on your platform.  See https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Applytimezoneoffsetstotimestamps#zoneinfo_.2...

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

It depends on your platform.  See https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Applytimezoneoffsetstotimestamps#zoneinfo_.2...

---
If this reply helps you, Karma would be appreciated.

kscher
Path Finder

That wraps it up perfectly; thanks!

I’m not sure why that little nugget was so hard (for me at least) to find. “Getting Data In” was not where I expected it to show up, since we were looking at search-time strptime().

Thanks again.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...