Splunk Search

Do I need to restart Splunk after a daylight savings change?

Jason
Motivator

I'm looking at a client system right now that has the following:

  • the event has a timestamp of 18:00:00
  • the Splunk extrapolated time (in gray next to it on flashtimeline) of 18:00:00
  • the flash histogram above it (zoomed into a one-minute time interval) says 19:00:00

Does this just mean that daylight savings time has occurred and the splunkd hasn't yet been restarted?

Tags (3)
0 Karma

russellliss
Path Finder

I found that changing your timezone, and researching updates the extrapolated time, but I needed to logoff to have the histogram update to the correct time.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...