All Apps and Add-ons

Splunk DB Connect + McAfee Add-on: How to set correct timezone?

PabloJulian
New Member

Hello all,

We are connecting to our McAfee database using the McAfee Add-on 2.2.1 and DBConnect 3.3.1.

The search reads perfectly; however, the McAfee database timestamps are in UTC time. On the database connection, we have defined our timezone as Canada/Eastern: -04:00.

However, the timestamps are still shown in UTC time. I was expecting the timestamps to be converted by DB Connect to the actual timezone where they're in. Is there any way to do that?

Btw I've tried the solutions in answer 612262 and 620601 to no avail:

Setting correct timezone for mcafee logs in dbconnect: https://answers.splunk.com/answers/612262/index.html
How can I override the timezone for Splunk DBX 3.1?: https://answers.splunk.com/answers/620601/index.html

Thanks all,

Pablo

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...