I am using Splunk dbConnect to collect data from database. While configuring the connection, set the timezone as Etc/GMT+1 : -01:00 as the logs generation time in database is GMT+1
When I was searching the data and searched for time difference, got time difference of 1 hour, _time is 1 hr ahead of indextime.
FYI: The database is in GMT+1
What is the difference between Etc/GMT+1 : -01:00 and Etc/GMT-1 : +01:00 ?
Thank you for any help!
Try choosing TZ GMT+1 not etc/gmt+1 in database connections.
I do not see any TZ like GMT+1, its Etc/GMT+1: -01:00 and Etc/GMT-1:+01:00
choose based on your area. there are so many for +1, but don't choose the one with etc.