All Apps and Add-ons

Using splunk db connect to send data from db, which is timestamped in GMT, set user preference to EST in portal, data can not be found using last 4 hours, because data is in the future

rileyken2
Path Finder

Using splunk db connect to send data from db, which is timestamped in GMT, set user preference to EST in portal, data can not be found using last 4 hours, because data is in the future

Only workaround is to select 'all time" which is not great

0 Karma
1 Solution

rileyken2
Path Finder
0 Karma

rileyken2
Path Finder

typically I just use a known sourcetype like "access_combined", but in this case the db connect handles that set up, not sure what it is and there is nothing in the application installation docs that give details on how to configure.

I did try passing a arg to the JVM on start up, setting the TZ to UTC.. did not see to matter

0 Karma

rileyken2
Path Finder

on the heavy forwarder running the db connect or the indexer (all in one)?

the answer in both cases is default, I have not tried that

0 Karma

richgalloway
SplunkTrust
SplunkTrust

So that's your first problem. Every input should have a sourcetype defined and that definition should include, at a mininum, TIME_PREFIX, TIME_FORMAT, MAX_TIMESTAMP_LOOKAHEAD,LINE_BREAKER, andTRUNCATE`.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are the props.conf settings for the sourcetype?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...