Hi All,
The timezone in my splunk setup is IST (UTC + 5.30)
From the examples at http://docs.splunk.com/Documentation/Splunk/5.0.3/Search/Specifytimemodifiersinyoursearch
if the current time is Jul 4, 2013 8:11:56.000 PM
Then -1h@h = Jul 4, 2013 7:00:00.000 PM
But in my setup, when the current time is
Jul 4, 2013 8:11:56.000 PM
-1h@h
returns Jul 4, 2013 6:30:00.000 PM
Taking into account the conversion of time between UTC and IST, is this behavior correct?