Using splunk db connect to send data from db, which is timestamped in GMT, set user preference to EST in portal, data can not be found using last 4 hours, because data is in the future
Only workaround is to select 'all time" which is not great
I found the solution to my issue here:
https://answers.splunk.com/answers/512913/splunk-db-connect-how-to-set-correct-timezone-for.html
I found the solution to my issue here:
https://answers.splunk.com/answers/512913/splunk-db-connect-how-to-set-correct-timezone-for.html
typically I just use a known sourcetype like "access_combined", but in this case the db connect handles that set up, not sure what it is and there is nothing in the application installation docs that give details on how to configure.
I did try passing a arg to the JVM on start up, setting the TZ to UTC.. did not see to matter
on the heavy forwarder running the db connect or the indexer (all in one)?
the answer in both cases is default, I have not tried that
So that's your first problem. Every input should have a sourcetype defined and that definition should include, at a mininum, TIME_PREFIX
, TIME_FORMAT
, MAX_TIMESTAMP_
LOOKAHEAD,
LINE_BREAKER, and
TRUNCATE`.
What are the props.conf settings for the sourcetype?