Hi,
im having a problem with database inputs conversion of date and time.
my database table date and time format is YYYY-MM-DD/HH:mm:ss but Splunk was able to read this differently.
sample:
"DB table date and time": 2016-11-25/17:56:00
"Splunk converted date and time":
(Record 1) 2016-11-25 7:59:59:000 AM
(Record 2) 2016-11-25 7:59:59:000 AM
(Record 3) 2016-11-25 7:59:59:000 AM
Can this be solved by revising the SQL? or by regex?
Hello,
You should be able to define the timestamp for the specific connection in $SPLUNK_HOME/etc/apps/splunk_app_db_connect/local/inputs.conf
Here you can enter output_timestamp_format = yyyy-MM-dd HH:mm:ss
Did you set this?