Splunk Enterprise Security

Rules Time Zones

astatrial
Contributor

Hi All,

I need to build a rule that alerts for specific activity by specific user past working hours.

For example:

I want to alert when user "Dani" logs in to the computer not between 7:00 - 18:00.

The problem is that the user is not in the same time zone as me.

So login logs at 19:00 in my time zone can be actually at 14:00 in the other user time zone.

-  Does anyone know what is the time zone that the rules go by?

-  Is it set by the configuration of the user that the rule is running as? 

 

Thanks ! 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, the rules use the time zone of the user running the rule.

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Thanks for the fast reply.

 

If the time zone of the user is changed? Does it also changed for the rules?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...