Getting Data In

Does Splunk has a feature to auto detect the timezone of the viewer?

Cbr1sg
Path Finder

Hello all,
I have an use case in Splunk to display the data in the viewer's timezone automatically.

For example: when an user in Singapore sees the data, the time of the event will be calculated according to +8 timezone, while it will be +5:30 timezone when an user in India view the exact same data.

Does Splunk have a feature to auto-detect the timezone of the viewer (maybe from Operating System time)? If no, do you have an alternative solution for this use case?

Thanks

Tags (2)
0 Karma

renjith_nair
Legend

@Cbr1sg ,
Users can select the preferred timezone in the browser by selecting your Username ->Account Settings and select the required timezone from the available timezone drop-down. Events timestamp will be shown based on that timezone. If you are an admin, you could set this for individual users - http://docs.splunk.com/Documentation/Splunk/7.1.2/Security/ConfigureuserswithSplunkWeb

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

Cbr1sg
Path Finder

I'm aware of this, but I dont want to do this way since we have more than 100K of viewers (include VIP) and we can't probably ask every single user to do it. Would be much better if Splunk can detect the timezone automatically from viewer's computer time

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk automatically converts times into the timezone selected by the viewer in his Splunk profile.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Cbr1sg
Path Finder

same comment as above, I'm aware of this, but I dont want to do this way since we have more than 100K of viewers (include VIP) and we can't probably ask every single user to do it. Would be much better if Splunk can detect the timezone automatically from viewer's computer time

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk does not detect the user's timezone automatically so the manual option is all there is. Feel free to submit an RFE.

IMO, it's perfectly reasonable to expect users to specify the time zone in which they want to see times displayed. It only has to be done once and only by those who don't want the default setting.

---
If this reply helps you, Karma would be appreciated.

Cbr1sg
Path Finder

Yes I totally agree with you in someway it's very reasonable to expect users to specify the timezone themselves once. However there are multiple types of user and some of them just doesn't want to do extra little steps.
IMO, the feature to detect the system time from user's computer is not something new, seen it in many websites nowsaday, should be something that Splunk can implement easily. I will submit RFE then, thanks for your suggestion.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...