Hi,
I'm creating a multisite Splunk deployment with timezone differences. Since most users do not change their timezone perf and it's set to default, it could change depending on which search head and indexer they pull from. Is there a configuration setting that would set the timezone for the entire Splunk environment? I would imagine I would need to set the indexers and the search heads to ensure the results are static, correct? Any recommendations on how I should approach this?
TIA,
Todd
↧