We are running into an issue where we have multiple users across the country; specifically MST. Data resideds on a server in CST. The users in MST is responsible for the searches/alerts and ran into a problem w/false alerts. We've discovered that it's because the saved search runs under the timezone of the user who created it.
I can think of a few workarounds but I want to know if there is a way to instruct splunk to run the scheduled search under a certain timezone?
... View more