Hello!
Daylight saving time here in Brazil has been canceled, the time will stay UTC / GMT
-03: 00.
What can be carried out in Splunk so this timezone is picked up?
I configured props.conf, but in dbconnect 3.0.1 it ignores the configuration and continues using the Server timezone (Windows).
Thank you!
You want the fix at ingestion time or search time?
I want the fix at ingestion!
Thanks.
The solution was informed by Splunk support.
"Include the" -Duser.timezone = America / Stronghold "parameter in the DBConnect app's general settings. In the APP" Settings "option."
Thanks!