Configure user language and locale
When a user logs in, Splunk automatically uses the language that the user's browser is set to. To switch languages, change the browser's locale setting. Locale configurations are browser-specific.
Splunk detects locale strings. A locale string contains two components: a language specifier and a localization specifier. This is usually presented as two lowercase letters and two uppercase letters linked by an underscore. For example, "en_US" means US English and "en_GB" means British English.
The user's locale also affects how dates, times, numbers, etc., are formatted, as different countries have different standards for formatting these entities.
Splunk provides built-in support for these locales:
de_DE en_GB en_US fr_FR it_IT ja_JP ko_KR zh_CN zh_TW
If you want to add localization for additional languages, refer to "Translate Splunk" in the Developer manual for guidance. You can then tell your users to specify the appropriate locale in their browsers.
How browser locale affects timestamp formatting
By default, timestamps in Splunk are formatted according the browser locale. If the browser is configured for US English, the timestamps are presented in American fashion:
MM/DD/YYYY:HH:MM:SS. If the browser is configured for British English, then the timestamps will be presented in the European date format:
For more information on timestamp formatting, see "Configure timestamp recognition" in the Getting Data In manual.
Override the browser locale
The locale that Splunk uses for a given session can be changed by modifying the url that you use to access Splunk. Splunk urls follow the form
http://host:port/locale/.... For example, when you access Splunk to log in, the url may appear as
http://hostname:8000/en-US/account/login for US English. To use British English settings, you can change the locale string to
http://hostname:8000/en-GB/account/login. This session then presents and accepts timestamps in British English format for its duration.
Requesting a locale for which the Splunk interface has not been localized results in the message:
Invalid language Specified.
Refer to "Translate Splunk" in the Developer Manual for more information about localizing Splunk.
About users and roles
Configure user session timeouts
This documentation applies to the following versions of Splunk® Enterprise: 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.6.0, 6.6.1