I have a dashboard that has 2 real time search counts and all the other panels are based on scheduled searches. The real time counts events on last 5 minutes. On the upper corner of each panel it displays the last time the search has been ran. It will say refreshed at hh:mm. The scheduled searches have the correct eastern time which is the time of the server and the logs. The real time search however is displaying my time zone (central time). Does that timestamp reflect the timezone of the browser or this being set somewhere?
There is a user/login-level setting that tells Splunk how to normalize timestamps when presenting data to each user. It is in Settings
-> Edit Account
-> Times zone
. This normalized time is shown only if you select List
or Table
(e.g. not Raw
) in the upper-left corner above the search results. Doing so creates a Time
column next to the Event
column. Do you see this?
Did this help?