Hi all,
In DB Input of DB CONNECT, inside PARAMETERS, I configured to CHOOSE COLUMN on timestamp, instead default option (CURRENT INDEX TIME), and select my column that have a date.
When I go on search page, any event are one more year. For example: The correct date of event is 29/12/2014, but the splunk event show 29/10/2015 (December of this year).
Does anybody can help me, please?
Thanks!
↧