<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic troubleshooting. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679142#M18781</link>
    <description>&lt;P&gt;Am getting a warning of&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;  DateParserVerbose - Accepted time (Wed Feb 14 17:01:12 2024) is suspiciously far away from previous event  (Thu jan  18 17:01:12 2024) is still acceptable because it was extracted by the same pattern&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;Is there any configuration that can help take this error away in splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 15:42:10 GMT</pubDate>
    <dc:creator>whitecat001</dc:creator>
    <dc:date>2024-02-29T15:42:10Z</dc:date>
    <item>
      <title>troubleshooting.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679142#M18781</link>
      <description>&lt;P&gt;Am getting a warning of&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;  DateParserVerbose - Accepted time (Wed Feb 14 17:01:12 2024) is suspiciously far away from previous event  (Thu jan  18 17:01:12 2024) is still acceptable because it was extracted by the same pattern&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;Is there any configuration that can help take this error away in splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 15:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679142#M18781</guid>
      <dc:creator>whitecat001</dc:creator>
      <dc:date>2024-02-29T15:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679178#M18783</link>
      <description>&lt;P&gt;Make sure the props.conf settings for that sourcetype have the correct time settings.&amp;nbsp; Specifically, check the TIME_PREFIX, TIME_FORMAT, and MAX_TIMESTAMP_LOOKAHEAD values.&lt;/P&gt;&lt;P&gt;Confirm the data source is sending the right events.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:59:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679178#M18783</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-29T16:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679183#M18784</link>
      <description>Quite possibly there are missing time format on your props.conf. For that reason splunk guess between mm/dd/yyyy and dad/mm/yyyy formats.</description>
      <pubDate>Thu, 29 Feb 2024 17:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679183#M18784</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-29T17:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679196#M18785</link>
      <description>&lt;P&gt;The first event that came in doesnt have a timestamp which is the reason for the error but the other events are extracted properly&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 20:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/troubleshooting/m-p/679196#M18785</guid>
      <dc:creator>whitecat001</dc:creator>
      <dc:date>2024-02-29T20:04:26Z</dc:date>
    </item>
  </channel>
</rss>

