Hi, using 2.3.0 improves the UI of this area, so it's worth going there... here's the docs section for doing inputs:
http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/Createandmanagedatabaseinputs
If your column is already datetime format in the database, you can just click it and we should be good.
If it's not, you can click it and specify an override format in Java style
Or you can modify your SQL to issue a friendly format: http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/SQLtipsandtricks
note that you might need to use props.conf to deal with timezone (for instance the database is in UTC and has global times, but your Splunk is in local and therefore sees some of the records as coming from the future).
... View more