<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to edit Splunk Cloud DATETIME_CONFIG=CURRENT? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-Splunk-Cloud-DATETIME-CONFIG-CURRENT/m-p/629349#M107958</link>
    <description>&lt;P&gt;You say you "chose to use a sourcetype".&amp;nbsp; How did you implement that decision?&amp;nbsp; It sounds like the add-on is not using that sourcetype.&amp;nbsp; When you look at the events that have the wrong timestamp, check the sourcetype value associated with them.&amp;nbsp; That is the sourcetype you need to modify to use &lt;FONT face="courier new,courier"&gt;DATETIME_CONFIG=CURRENT&lt;/FONT&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2023 14:34:16 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-02-02T14:34:16Z</dc:date>
    <item>
      <title>How to edit Splunk Cloud DATETIME_CONFIG=CURRENT?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-Splunk-Cloud-DATETIME-CONFIG-CURRENT/m-p/629263#M107951</link>
      <description>&lt;P&gt;I have a json source with input via a Splunk Add-on for AWS input. Sometimes there's a timestamp-like field, sometimes not, so I chose to use a sourcetype with Timestamp handling set to "Current time" in the GUI which I think sets DATETIME_CONFIG=CURRENT in the sourcetype's props.conf entry.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I expected this to mean that's where the events would get their timestamp from, but log messages in splunkd.log (according to what I see in index=_internal) are still showing that DateParserVerbose is spitting&amp;nbsp;out warnings that "&lt;SPAN&gt;A possible timestamp match ...&amp;nbsp;is outside of the acceptable time window" occurring when events with no recognisable time are indexed. This also means that some events get seemingly random timestamps if some string gets misinterpreted; a handful of events generated yesterday had timestamps in November 2021.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Was I wrong expecting a sourcetype's DATETIME_CONFIG worked that way?&lt;BR /&gt;&lt;BR /&gt;If not, what might be happening to stop my intended timestamping?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If so, how else should I handle events with no&amp;nbsp;timestamps?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks for any advice.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 02:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-Splunk-Cloud-DATETIME-CONFIG-CURRENT/m-p/629263#M107951</guid>
      <dc:creator>SeanBatt</dc:creator>
      <dc:date>2023-02-02T02:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit Splunk Cloud DATETIME_CONFIG=CURRENT?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-Splunk-Cloud-DATETIME-CONFIG-CURRENT/m-p/629349#M107958</link>
      <description>&lt;P&gt;You say you "chose to use a sourcetype".&amp;nbsp; How did you implement that decision?&amp;nbsp; It sounds like the add-on is not using that sourcetype.&amp;nbsp; When you look at the events that have the wrong timestamp, check the sourcetype value associated with them.&amp;nbsp; That is the sourcetype you need to modify to use &lt;FONT face="courier new,courier"&gt;DATETIME_CONFIG=CURRENT&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 14:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-Splunk-Cloud-DATETIME-CONFIG-CURRENT/m-p/629349#M107958</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-02-02T14:34:16Z</dc:date>
    </item>
  </channel>
</rss>

