Hi guys,
I had the same problem.
Problem: Splunk connected via DBConnect v2 in SQL, recorded time field in SQL with GMT timezone, but Splunk interprets the data as localtime.
Changing the configuration file Splunk \ etc \ apps \ splunk_app_db_connect \ Local \ props.conf include the TZ settings the result is the same, nothing changes.
The TZ parameter configuration works out of DBConnect v2.
My solution in SQL:
SELECT CONVERT (datetime, SWITCHOFFSET (CONVERT (datetimeoffset, MyTable.UtcColumn) DATENAME (TzOffset, SYSDATETIMEOFFSET ()))) AS ColumnInLocalTime FROM MyTable
Works, just run the query in DBConnect v2.
... View more