Getting Data In

Splunk dbConnect inputs

chaitali_1994
Engager

I am using Splunk dbConnect to  collect data from database. While configuring the connection, set the timezone as Etc/GMT+1 : -01:00 as the logs generation time in database is GMT+1

When I was searching the data and searched for time difference, got time difference of 1 hour, _time is 1 hr ahead of indextime.

 

FYI: The database is in GMT+1

What is the difference between Etc/GMT+1 : -01:00 and Etc/GMT-1 : +01:00 ?

 

Thank you for any help!

Labels (1)
Tags (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Try choosing TZ GMT+1 not etc/gmt+1 in database connections. 

————————————
If this helps, give a like below.
0 Karma

chaitali_1994
Engager

I do not see any TZ like GMT+1, its Etc/GMT+1: -01:00 and Etc/GMT-1:+01:00

0 Karma

thambisetty
SplunkTrust
SplunkTrust

choose based on your area. there are so many for +1, but don't choose the one with etc.

Screen Shot 2020-08-07 at 3.46.57 PM.png

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...