Getting Data In

Summary indexes and multiple time zones

sc0tt
Builder

In an environment that provides reporting across many different time zones, should summary searches run under a user set to the default system time, GMT time, or doesn't it matter since Splunk will adjust the time based on the user's time zone?

0 Karma

woodcock
Esteemed Legend

Generally, it doesn't matter because the _time field that is created for the events in the summary index is always normalized to GMT epoch. There is one thing to consider, though; if you are using any snap-to definitions, these may be effected by the user's Time zone value. For example, if your TZ offset is not an even-hour (I just read that North Korea is dropping 30 minutes from their TZ), then @h for one user may be 30 minutes different than @h for another user. The same concern exists for relative day specifiers anywhere they exist (not just for the snap-to part) because where midnight falls (e.g. where the DayChange time is), may be different for different users so the window for day can be different from user-to-user.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...