Hi,
I am ingesting data into Splunk using Dbconnect 3.X version JTDS driver.
My database field format is : Date with UTC timezone.
I wanted to have data ingested into Splunk using Local timezone.
**Current Arch:**
Database <-> Dbconnect HF (jTDS) <--> Splunk Indexer (or Instance)
**Attempted Fix:**
1. Modified Db connections conf and added localTimezoneConversionEnabled = true & timezone = Australia/Melbourne
but that didn't work.
2. Try to modify Props.conf on Splunk instance and have added TZ value but didnt work.
3. Tried Modifying query and added DATEADD but it does not corporate DST.
↧