In Splunk, when you are the owner of a scheduled alert, the cron expression is interpreted based on your personal time zone setting.
So if you change your time zone (e.g., from UTC to PDT), the cron schedule will shift accordingly, and the next scheduled time will be recalculated based on the new time zone.
Go to Settings → Searches, Reports, and Alerts
Select the app where your alert is configured (e.g., abcd
)
Find your alert and check the Next Scheduled Time column
This is the most reliable way to confirm when your alert will actually run.