The clock on my server didn't adjust to the proper time for DST. I have updated the clock and restarted the server. However, when I set relative time on any of my searches, the time window it sets for searching is off by an hour. For example, if I set:
earliest=-1d@d
Splunk returns results from 1:00 am the previous night, rather than from midnight.
I have the timezone set in props.conf as TZ = America/Chicago
How can I get the time corrected so that relative time searches work properly? Any help is appreciated!
For anyone interested, I resolved this problem by cleaning the index, then re-indexing all my events after correcting the system clock.
For anyone interested, I resolved this problem by cleaning the index, then re-indexing all my events after correcting the system clock.