<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default datetime fields in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578498#M102143</link>
    <description>&lt;P&gt;Is there a way in which I can force the year based on the source of the historical data, i.e the directory path for the data?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Dec 2021 15:45:58 GMT</pubDate>
    <dc:creator>Martin583</dc:creator>
    <dc:date>2021-12-15T15:45:58Z</dc:date>
    <item>
      <title>Default datetime fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578468#M102136</link>
      <description>&lt;P&gt;I am using Splunk to Search historical data in a virtual index but I have noticed that the default date_year is being incorrectly added.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My data is from 2020 and when I search I specified a source pointing to a&amp;nbsp; particular directory based on the date at which it was ingested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately the logs in question have a timestamp in the following format &lt;STRONG&gt;%b %e %H:%M:%S&lt;/STRONG&gt; i.e no year..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run my search looking in the folder for 15/08/2020 some of the default dates are 2020 but some are 2021.&lt;/P&gt;&lt;P&gt;index=vix_web&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source="/data/xx/xxx/xxx/xxx/2020/08/15"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having done some research on how the default times are extracted, it would seem&amp;nbsp; datetime.xml is used but I still don't know where the year is extracted from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 13:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578468#M102136</guid>
      <dc:creator>Martin583</dc:creator>
      <dc:date>2021-12-15T13:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Default datetime fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578485#M102139</link>
      <description>&lt;P&gt;You should get your answer here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps#How_Splunk_software_assigns_timestamps" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/HowSplunkextractstimestamps#How_Splunk_software_assigns_timestamps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;under the section :&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;How Splunk software determines timestamps with no year&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 14:28:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578485#M102139</guid>
      <dc:creator>ldongradi_SPL</dc:creator>
      <dc:date>2021-12-15T14:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Default datetime fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578492#M102141</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;What I don't understand is that for some months of the historical data for the same types of events it will have a default date_year which is correct i.e 2020 but some that come back as 2021.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 15:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578492#M102141</guid>
      <dc:creator>Martin583</dc:creator>
      <dc:date>2021-12-15T15:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Default datetime fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578497#M102142</link>
      <description>&lt;P&gt;Following the logic in the article I would think that the vast majority of the Historical logs should infact have 2021 applied to them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 15:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578497#M102142</guid>
      <dc:creator>Martin583</dc:creator>
      <dc:date>2021-12-15T15:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Default datetime fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578498#M102143</link>
      <description>&lt;P&gt;Is there a way in which I can force the year based on the source of the historical data, i.e the directory path for the data?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 15:45:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-datetime-fields/m-p/578498#M102143</guid>
      <dc:creator>Martin583</dc:creator>
      <dc:date>2021-12-15T15:45:58Z</dc:date>
    </item>
  </channel>
</rss>

