Hi,
The Search Time Modifiers do not work properly when half hour time zones are set.
(There are very few countries who still follow half hour time zones. http://www.timeanddate.com/time/time-zones-interesting.html)
We cannot set timezone on splunk to these countries' local timezone.
Earlier there were questions raised on this:
http://answers.splunk.com/answers/93923/time-modifiers-for-search-and-time-zones
http://answers.splunk.com/answers/144736/splunk-summarization-occuring-for-wrong-time-range
Is this a bug? Before opening a case with Splunk, I thought of checking with splunkers here.
Thanks,
Strive
From the information provided in those answers, I don't have the whole picture.
For example if the data is expressed in IST, and the searcher is in a timezone such as UTC or America/New_York, then -1h@h should snap to an hour-boundary in the user's timezone which would look like half-hour boundaries in the IST expressed time.
However it seems that people are saying that when the data is in IST and the user is in IST that -1@h maps to a half-hour boundary. That would be a defect.