Reporting

When a report is scheduled for a specific time using cron; Does the report run from the System timezone, or the user timezone?

mcrawford44
Communicator

When a report is scheduled for a specific time using cron; Does the report run from the System timezone, or the user timezone?

For example;

User from EST schedules a report to run via cron at 9pm.

Server time is PST.

When does the report run?

Tags (2)

TStrauch
Communicator

Hi mcrawford,

Known issue in Splunk 6.2:

2014-12-01 SPL-92736 Scheduler ignores user/owner user_pref time zone setting for cron scheduled searches, runs cron scheduled search in relation to system time.

Resolved with this:

2015-04-15 SPL-92736 The scheduler uses the server timezone (GMT) to run scheduled searches, instead of the user timezone preferences, impact the alerts, reports, and summary indexing.

Means until today the cron based scheduler takes the System Time Zone to schedule the Report.

Have a nice day 😉

somesoni2
Revered Legend

Server time zone

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...