i know this is an old forum but i had the similar problem and found the settings localTimezoneConversionEnabled fixed my issues. Hopefully can help someone else in the future. vi /splunk/etc/apps/splunk_db_connect/local/db_connections.conf Under your connection stanza find the localTimezoneConversionEnabled and set it to true as its false by default. DBConnect > Configuration > Settings > General > Click Save to restart/reload settings
... View more