Splunk Enterprise Security

Rules Time Zones

astatrial
Contributor

Hi All,

I need to build a rule that alerts for specific activity by specific user past working hours.

For example:

I want to alert when user "Dani" logs in to the computer not between 7:00 - 18:00.

The problem is that the user is not in the same time zone as me.

So login logs at 19:00 in my time zone can be actually at 14:00 in the other user time zone.

-  Does anyone know what is the time zone that the rules go by?

-  Is it set by the configuration of the user that the rule is running as? 

 

Thanks ! 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, the rules use the time zone of the user running the rule.

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Thanks for the fast reply.

 

If the time zone of the user is changed? Does it also changed for the rules?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...