The problem with both of those is it does not account for the 5 vs 6 hour shift between CDT and CST. That is, solutions like this that use relative_time, manually subtract 5 or 6 hours, but do not differentiate when to make that shift (March-ish to November-ish), but Splunk has TZ awareness since the user can set their profile. Seems like there should be a way (a function?) to tap into that, but something like relative_time(epoch, "CST6CDT") doesn't seem exist. Many thanks for the great conversation as, per usual, learning!
... View more