Hello splunkers, I have this search:
index = "sti" sourcetype = "Genera_AVI" | fields _time | head 1 | eval tiempo = strftime(now(),"%H:%M:%S") | table tiempo
now() show following time:
13:36:15
But actually it's 12:36
Is it problem with server hour? Where I change it? I have a cluster indexer
check your account settings for timezone, probably its set to EST and you are in CST zone?
This changed only my account.
Exist a way to change for all users?
@rjfv8205 You can let the users change their own timezones. If you want to forcefully change all users timezones then you need to modify user-prefs.conf for all users. See this link below , may be of help-
https://answers.splunk.com/answers/126350/change-multiple-users-timezone.html