Splunk needs to fix this bug. date_hour should use the offset time specified in props.conf . Why have different behaviors for time across different operators (timechart offsets via props.conf TZ=GMT setting, but date_hour does not)? At least add us a local_date_hour . @BenjaminWyatt - this works for CST offset from GMT: eval date_hour = date_hour-6 | eval date_hour = if(date_hour<0, 24 + date_hour, date_hour) to account for negative date hours.
... View more