<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reports are not indexed correctly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Reports-are-not-indexed-correctly/m-p/670245#M112388</link>
    <description>&lt;P&gt;I have a single search head and configured the props.conf to have DATETIME_CONFIG = CURRENT as I want the data to be indexed at the time Splunk receives the report. I restarted splunk after every change.&lt;/P&gt;&lt;P&gt;Previously I had it set to a field in the report. When I upload a csv and use the correct sourcetype it assigns the current time to the report. When I upload a report via curl through the HEC endpoint it indexes it to the right time. Same thing when I run it through a simple script.&lt;/P&gt;&lt;P&gt;But when the test pipeline runs, it indexes data to the timestamp that is in the report even though it is using the same sourcetype as the other tests I did. Is it possible to add a time field that overrides the sourcetype config? Is there a way to see the actual api request in the splunk internal logs?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2023 00:25:00 GMT</pubDate>
    <dc:creator>klim</dc:creator>
    <dc:date>2023-11-30T00:25:00Z</dc:date>
    <item>
      <title>Reports are not indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reports-are-not-indexed-correctly/m-p/670245#M112388</link>
      <description>&lt;P&gt;I have a single search head and configured the props.conf to have DATETIME_CONFIG = CURRENT as I want the data to be indexed at the time Splunk receives the report. I restarted splunk after every change.&lt;/P&gt;&lt;P&gt;Previously I had it set to a field in the report. When I upload a csv and use the correct sourcetype it assigns the current time to the report. When I upload a report via curl through the HEC endpoint it indexes it to the right time. Same thing when I run it through a simple script.&lt;/P&gt;&lt;P&gt;But when the test pipeline runs, it indexes data to the timestamp that is in the report even though it is using the same sourcetype as the other tests I did. Is it possible to add a time field that overrides the sourcetype config? Is there a way to see the actual api request in the splunk internal logs?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 00:25:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reports-are-not-indexed-correctly/m-p/670245#M112388</guid>
      <dc:creator>klim</dc:creator>
      <dc:date>2023-11-30T00:25:00Z</dc:date>
    </item>
  </channel>
</rss>

