I'm having two problems with splunk dashboards after I upgraded to 7.1.2. These only seem to occur when searching Date range or date-time range on dashboards. Making a custom search returns correclty. Relative time also works fine.
Dashboards are using the searching computer's timezone as a base.
Dashboards aren't converting the shared timepicker based on the timezone
I made 2 accounts, account A in my computer's local time (PST, -7 hrs since daylight savings) and account B in my splunk server's time (GMT).
I make a timerange search since today (date range, since today) on my local computer. Account A returns from midnight (as expected) while account B returns from 7:00AM (PST as base time). in the URL the epoch time for both searches is the same, midnight PST epoch.
I make a timerange search since today (date range, since today) on my splunk server. Account A returns from 5PM the previous day (GMT as base time) while account B returns from midnight (as expected). in the URL the epoch time for both searches is now midnight GMT epoch.
I've been looking into this for several days and I'm led to believe its a bug with splunk as I have another splunk host (unrelated to this instance, different data) which is still on 6.3 and the dashboard timeranges work correctly as expected. Help would be appreciated.
... View more