Splunk Search

Relative search time off by an hour

wpreston
Motivator

The clock on my server didn't adjust to the proper time for DST. I have updated the clock and restarted the server. However, when I set relative time on any of my searches, the time window it sets for searching is off by an hour. For example, if I set:

earliest=-1d@d

Splunk returns results from 1:00 am the previous night, rather than from midnight.

I have the timezone set in props.conf as TZ = America/Chicago

How can I get the time corrected so that relative time searches work properly? Any help is appreciated!

Tags (1)
0 Karma
1 Solution

wpreston
Motivator

For anyone interested, I resolved this problem by cleaning the index, then re-indexing all my events after correcting the system clock.

View solution in original post

wpreston
Motivator

For anyone interested, I resolved this problem by cleaning the index, then re-indexing all my events after correcting the system clock.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...