Dashboards & Visualizations

Can you help us change the time zone in preferences page for a dashboard?

siva_cg
Path Finder

Hi

We have a Splunk environment with clustered indexers and a distributed search head running on the 7.1.3 version. All servers are in Belgium time zone (CET).

As we have users across the globe, we decided to use GMT as user time zone in the preferences page. Using this setting, when we select a time range in a dashboard panel, it is showing according to CET time zone rather than GMT time zone.

For example: If we select time range as earliest=31/10/2018 00:00:00 and latest=31/10/2018 10:00:00, then the graph is showing from earliest=30/10/2018 23:00:00 and latest=31/10/2018 09:00:00.

Also, this behavior is being observed only in dashboards but not for ad-hoc searches. Could you please help me to understand this pattern? Thanks in advance.

0 Karma

ivanreis
Builder

My suggestion is to create an app and add the user-prefs.conf the stanza below. Make sure the users that is assigned to the particular role should see the GMT time zone. Maybe you should create a new role and assign all the users that should have to see the GMT time to this role and add the stanza below.

[role_user]
tz = GMT

https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/User-prefsconf#user-prefs.conf.example

0 Karma

FrankVl
Ultra Champion

Are you hardcoding that timerange in the search behind the dashboard, or are you using the timepicker? And what user is used to execute the search behind the dashboard? Is that the end user, or are the searches ran on behalf of some other user (with other timezone preference)?

0 Karma

siva_cg
Path Finder

Hi @FrankVI,

we are using timepicker and search is being run by end user.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...