Splunk Search

Do I need to restart Splunk after a daylight savings change?

Jason
Motivator

I'm looking at a client system right now that has the following:

  • the event has a timestamp of 18:00:00
  • the Splunk extrapolated time (in gray next to it on flashtimeline) of 18:00:00
  • the flash histogram above it (zoomed into a one-minute time interval) says 19:00:00

Does this just mean that daylight savings time has occurred and the splunkd hasn't yet been restarted?

Tags (3)
0 Karma

russellliss
Path Finder

I found that changing your timezone, and researching updates the extrapolated time, but I needed to logoff to have the histogram update to the correct time.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...