Hello.
Splunk version - 8.2.2
Splunk DB connect version - 3.6.0.
After update Splunk Enterprise version from 8.0.2 to 8.2.2. i have noticed problem with timezone for Oracle database sources.
My timezone is Europe/Kiev (GMT +3).
I set timezone in DB connection settings, also i have tried to set timezone at Java settings (-Duser.timezone=Europe/Kiev) but each time a have the same result.
So. I created DB connection with this select:
SELECT CAST(EXTENDED_TIMESTAMP AS TIMESTAMP)
EXTENDED_TIMESTAMP, AUDIT_TYPE, STATEMENT_TYPE, RETURNCODE
FROM SYS.DBA_COMMON_AUDIT_TRAIL
WHERE EXTENDED_TIMESTAMP > ?
ORDER BY EXTENDED_TIMESTAMP
Rising column - EXTENDED_TIMESTAMP
Time column - EXTENDED_TIMESTAMP.