<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-index after changing props.conf? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94428#M19642</link>
    <description>&lt;P&gt;I should mention that after the timestamp is the rest of the line with useful data that I'm searching for, I just did not include that here.&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2011 08:10:06 GMT</pubDate>
    <dc:creator>howyagoin</dc:creator>
    <dc:date>2011-05-04T08:10:06Z</dc:date>
    <item>
      <title>Re-index after changing props.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94427#M19641</link>
      <description>&lt;P&gt;Yesterday afternoon I updated a number of files which had missing data in them in a directory which Splunk's tailing processor was monitoring.  Before updating the files, I did a query for the specific source files and |'d through delete.&lt;/P&gt;

&lt;P&gt;After updating the files, the timestamps are not being read correctly and everything is attributed to yesterday's re-reading time:&lt;/P&gt;

&lt;PRE&gt;
5/3/11
12:52:25.000 PM INFO 2011-04-18 17:44
&lt;/PRE&gt;

&lt;P&gt;I thought I'd try to fix this by updating props.conf with:&lt;/P&gt;

&lt;PRE&gt;
[source::/A/B/c/dirwithfiles]
TIME_PREFIX = INFO\s
TIME_FORMAT = %Y-%m-%d %H:%m
&lt;/PRE&gt;

&lt;P&gt;Which I believe should be correct, but, the data is still incorrectly timestamped when I query -- I have the bad feeling, and am thus looking for confirmation here, that I have to remove and re-index everything for the props.conf to be read correctly.&lt;/P&gt;

&lt;P&gt;Yes?&lt;/P&gt;

&lt;P&gt;Or is there another way, a better way, a Splunktastic way?&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2011 08:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94427#M19641</guid>
      <dc:creator>howyagoin</dc:creator>
      <dc:date>2011-05-04T08:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Re-index after changing props.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94428#M19642</link>
      <description>&lt;P&gt;I should mention that after the timestamp is the rest of the line with useful data that I'm searching for, I just did not include that here.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2011 08:10:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94428#M19642</guid>
      <dc:creator>howyagoin</dc:creator>
      <dc:date>2011-05-04T08:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Re-index after changing props.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94429#M19643</link>
      <description>&lt;P&gt;Timestamp parsing applies as Splunk indexes new data, so any changes you make to that in props.conf will not affect data that has already been indexed. So, in order to get your timestamps right, you will indeed need to reindex your data after making your changes to props.conf (and restarting Splunk in order to activate these changes).&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2011 09:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94429#M19643</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-05-04T09:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Re-index after changing props.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94430#M19644</link>
      <description>&lt;P&gt;Thanks.  I was afraid of that.  I tried it on a few files and that seemed to be the result, but I was hoping to avoid the hassle and be told of a quicker way around it (and a way less likely to trip license issues given the amount of data...&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2011 09:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-index-after-changing-props-conf/m-p/94430#M19644</guid>
      <dc:creator>howyagoin</dc:creator>
      <dc:date>2011-05-04T09:34:05Z</dc:date>
    </item>
  </channel>
</rss>

