<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assign to missing timestamp event previous event timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Assign-to-missing-timestamp-event-previous-event-timestamp/m-p/709491#M117206</link>
    <description>If you want to use current time instead of time of previous event which are different to current time the you could in props.conf&lt;BR /&gt;DATETIME_CONFIG = [&amp;lt;filename relative to $SPLUNK_HOME&amp;gt; | CURRENT | NONE]&lt;BR /&gt;Select value CURRENT. But if the event time can be something else than current then probably not.</description>
    <pubDate>Wed, 22 Jan 2025 16:55:01 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-01-22T16:55:01Z</dc:date>
    <item>
      <title>Assign to missing timestamp event previous event timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Assign-to-missing-timestamp-event-previous-event-timestamp/m-p/709442#M117197</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;By default, if no timestamp exist in a field, Splunk defaulting timestamp of previous event&lt;/P&gt;&lt;P&gt;On one hand, I do want Splunk to do it, but on the other hand I don't want Splunk to treat it as a "Timestamp Parsing Issues" in the&amp;nbsp;Data quality.&lt;/P&gt;&lt;P&gt;Is there any way explicitly to tell Splunk to do it? I just want Splunk to treat it as error.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 10:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Assign-to-missing-timestamp-event-previous-event-timestamp/m-p/709442#M117197</guid>
      <dc:creator>michael_vi</dc:creator>
      <dc:date>2025-01-22T10:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Assign to missing timestamp event previous event timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Assign-to-missing-timestamp-event-previous-event-timestamp/m-p/709491#M117206</link>
      <description>If you want to use current time instead of time of previous event which are different to current time the you could in props.conf&lt;BR /&gt;DATETIME_CONFIG = [&amp;lt;filename relative to $SPLUNK_HOME&amp;gt; | CURRENT | NONE]&lt;BR /&gt;Select value CURRENT. But if the event time can be something else than current then probably not.</description>
      <pubDate>Wed, 22 Jan 2025 16:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Assign-to-missing-timestamp-event-previous-event-timestamp/m-p/709491#M117206</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-22T16:55:01Z</dc:date>
    </item>
  </channel>
</rss>

