Getting Data In

Users searching in different timezones

cramasta
Builder

my problem is that my indexer is in mountain time and everyone who uses splunk is in eastern time. So while everything is being indexed correctly, all my users have to be aware that there is a 2 hour time zone difference when searching by time, unless you specify to return the last 15m/60m/4h/24h which does exactly that, no matter what timezone you are in.

So now what would be the best solution. Change the timezone of the index server to eastern time or mess some more with the timezone settings in props.conf? Im learning towards changing the timezone of the server

Tags (1)
1 Solution

araitz
Splunk Employee
Splunk Employee

4.3, which was released a few months ago, supports per-user time zones on a single search head! Go Mitch! Nice question/suggestion!

View solution in original post

araitz
Splunk Employee
Splunk Employee

4.3, which was released a few months ago, supports per-user time zones on a single search head! Go Mitch! Nice question/suggestion!

gkanapathy
Splunk Employee
Splunk Employee

Easiest solution is to just have the users log into a new search head that is set to the desired time zone. This will adjust queries and results transparently. Changing the time zone of the indexer may (or may not) require you to go back and review all your input time zones, as any timestamp that is not otherwise indicated by a time zone is assumed to be in the same time zone as the indexer.

gkanapathy
Splunk Employee
Splunk Employee

4.2 does not. This functionality however is planned for version 4.3.

0 Karma

bmorgan
Explorer

I would like to know as well

0 Karma

beaumaris
Communicator

Is this still the recommendation under Splunk 4.2? Wondering if it has any better facilities for handling user-specific timezones, and having trouble locating that in the docs.

0 Karma

Genti
Splunk Employee
Splunk Employee

As far as i know there is nothing in the search language to tell splunk that you are doing a search that is relative to your timezone.
The quickest way to answer your question is, to have your users use the relative last 20 minutes, last 60 minutes etc.

Or perhaps, and i dont actually think i like this idea at all, you can even create your own time frames, modifying the xml file, (something like, you label the time to be 3, but instead it really is 1 for the server so when you are doing 3-5:00 for the server the timeframe is actually 1-3:00) but you better make sure that this only shows for eastern users, or it will confuse the hell out of your mountain time users.

Best approach i think is using relative time, you can even use earliest and latest

0 Karma

Genti
Splunk Employee
Splunk Employee

perhaps i am totally reading this wrong, but are these two statements not contradictory?

My issue is that when i have a splunk user who is in the eastern time zone do a look up in splunk specifying that they want events that occurred between 4 and 5pm the event does not show up because the splunk indexer sees it as happening at 3 pm.

and

It does seem like i have it set up correctly because when an event occurs on the agent at 5pm est and gets logged on the indexer at 3pm mountain, I (user in the eastern timezone) am able to at 5:05pm eastern do a search that is set to look at the past 15 minutes and the result that happened at 5pm eastern gets returned.

it could be that my brain is fried, but it seems to me like you are saying it doesnt work, on the first quote, but it does work on the second one..

0 Karma

cramasta
Builder

my brain was fried as well when i wrote this so im sure that didnt help.

My real problem is that my indexer is in mountain time and everyone who uses splunk is in eastern time. So while everything is being indexed correctly, all my users have to be aware that there is a 2 hour time zone difference when searching by time, unless you specify to return the last 15m/60m/4h/24h which does exactly that no matter what timezone you are in.

So now what would be the best solution. Change the timezone of the index server to eastern time?

Thanks for trying to make sense out of my rambling.
-Joe

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...