<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk data ingestion issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758449#M120243</link>
    <description>&lt;P&gt;i am uploading the data in the text format and that data contains logs but when i successfully upload the data of particular month some of the days of the data is missing or not searcheable when i check the data of perday it shows events of all the days but when i click on some of the days i got no results can you please tell me that what is my issue and where i am wrong so that i will create the proper and accurate dashboards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Feb 2026 10:54:03 GMT</pubDate>
    <dc:creator>harman</dc:creator>
    <dc:date>2026-02-18T10:54:03Z</dc:date>
    <item>
      <title>splunk data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758449#M120243</link>
      <description>&lt;P&gt;i am uploading the data in the text format and that data contains logs but when i successfully upload the data of particular month some of the days of the data is missing or not searcheable when i check the data of perday it shows events of all the days but when i click on some of the days i got no results can you please tell me that what is my issue and where i am wrong so that i will create the proper and accurate dashboards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 10:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758449#M120243</guid>
      <dc:creator>harman</dc:creator>
      <dc:date>2026-02-18T10:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758455#M120244</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315743"&gt;@harman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its hard to see without seeing the data, but it sounds to me like you might be suffering from date/time extraction issues. For example 03/02/2026 could end up as 2nd March OR 3rd Feb depending on if the date is extracted properly.&lt;/P&gt;&lt;P&gt;Are you adding the data through the Add Data section in the UI? Can you see the dates displayed in the preview window when doing this? Are you using a predefined sourcetype or have you made a custom sourcetype?&lt;/P&gt;&lt;P&gt;You may need to look at setting TIME_PREFIX and &lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.1/configuration-file-reference/9.1.0-configuration-file-reference/props.conf#:~:text=TIME_FORMAT%20%3D%20%3Cstrptime%2Dstyle%20format%3E" target="_self"&gt;TIME_FORMAT&lt;/A&gt; for your data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 11:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758455#M120244</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-02-18T11:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunk data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758458#M120245</link>
      <description>&lt;P&gt;I am uploading the june 2025, may 2025, and april 2025 data individually and i saw in every month the data for 9 to 10 days is missing&amp;nbsp; and when i apply the time filter like previous year then the events spread to all the months i have total 19,00,000 events per month approx but only 12,00,000 events are assigned to the june month other 7,00,000 events are assigned to the other months why i am stucked in this condition from 2 weeks&amp;nbsp; maybe it is the timestamp and date issue but i dont get it please help me and my logs contains the date format dd-mm-yy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 11:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758458#M120245</guid>
      <dc:creator>harman</dc:creator>
      <dc:date>2026-02-18T11:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: splunk data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758465#M120246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315743"&gt;@harman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your dates are in&amp;nbsp;&lt;SPAN&gt;dd-mm-yy&amp;nbsp; format then you need to specify a TIME_FORMAT value for your sourcetype, how you do this will depend on your setup - are you using a single instance through the UI to add this? If so when you're adding through the "Add Data" section then add the following:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT=%d-%m-%y &lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="livehybrid_0-1771421653796.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41448i3C8C0227557CBB6B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="livehybrid_0-1771421653796.png" alt="livehybrid_0-1771421653796.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 13:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758465#M120246</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-02-18T13:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758486#M120254</link>
      <description>&lt;P&gt;Ok I'll try this and verify that it works or not.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 05:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758486#M120254</guid>
      <dc:creator>harman</dc:creator>
      <dc:date>2026-02-19T05:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: splunk data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758487#M120255</link>
      <description>&lt;P&gt;And I am uploading the data through "Add Data" and that file is 350 mb large file and the limit is 500 mb for ingestion, But it is 100% valid and your very-very thanks for replying me!!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 05:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-data-ingestion-issue/m-p/758487#M120255</guid>
      <dc:creator>harman</dc:creator>
      <dc:date>2026-02-19T05:08:24Z</dc:date>
    </item>
  </channel>
</rss>

