<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DATETIME_CONFIG issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97937#M20430</link>
    <description>&lt;P&gt;my suggestion is :&lt;/P&gt;

&lt;P&gt;first, check your props.conf (which you had modified DATETIME_CONFIG=CURRENT ) is placed in heavy forwarder or indexer (if no heavy forwarder).&lt;/P&gt;

&lt;P&gt;second, check your props.conf is work (you should restart splunkd after you modify props.conf; and you should save your props.conf under $SPLUNK_HOME/etc/apps//local/ directory ), use "splunk btool --debug props list" to check if your setting is work&lt;/P&gt;</description>
    <pubDate>Wed, 21 Mar 2012 06:11:02 GMT</pubDate>
    <dc:creator>dmlee</dc:creator>
    <dc:date>2012-03-21T06:11:02Z</dc:date>
    <item>
      <title>DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97935#M20428</link>
      <description>&lt;P&gt;Im trying to base the timestamp in the logs on the current time using DATETIME_CONFIG = CURRENT in props.conf rather than Splunk extracting the timestamp I decided the the current time would be ok.&lt;/P&gt;

&lt;P&gt;The problem is it wont work, and my logs wont index only when I have the above set in props.conf&lt;/P&gt;

&lt;P&gt;Has this ever worked before?, or am Missing something here?&lt;/P&gt;

&lt;P&gt;Source: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Configuretimestamprecognition"&gt;link text&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2012 05:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97935#M20428</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-03-21T05:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97936#M20429</link>
      <description>&lt;P&gt;It works. Question - what is the full stanza in props.conf? Have you specified the source, sourcetype or host correctly in the stanza header?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2012 06:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97936#M20429</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-03-21T06:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97937#M20430</link>
      <description>&lt;P&gt;my suggestion is :&lt;/P&gt;

&lt;P&gt;first, check your props.conf (which you had modified DATETIME_CONFIG=CURRENT ) is placed in heavy forwarder or indexer (if no heavy forwarder).&lt;/P&gt;

&lt;P&gt;second, check your props.conf is work (you should restart splunkd after you modify props.conf; and you should save your props.conf under $SPLUNK_HOME/etc/apps//local/ directory ), use "splunk btool --debug props list" to check if your setting is work&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2012 06:11:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97937#M20430</guid>
      <dc:creator>dmlee</dc:creator>
      <dc:date>2012-03-21T06:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97938#M20431</link>
      <description>&lt;P&gt;I have been using splunk for over 2 years now, so Iv already checked all of the above, Thanks&lt;/P&gt;

&lt;P&gt;Its very confusing you see, I am actually forced to use the current timestamp all because Splunk wont ingest the %H:%M:S without having a Year Month or Day attached to it, I dont know where its getting those dates from to tell u the truth its very random&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2012 06:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97938#M20431</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-03-21T06:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97939#M20432</link>
      <description>&lt;P&gt;Yes I have, the name of the Sourcetype where its going to be ingested at&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2012 06:15:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97939#M20432</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-03-21T06:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97940#M20433</link>
      <description>&lt;P&gt;There is a way to have Splunk take the date from the file name (or file mod time) and the time from the event - but I can't find the documentation for it...&lt;/P&gt;

&lt;P&gt;Also, if the DATETIME_CONFIG=CURRENT isn't working, I would file a support ticket. This just seems wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2012 21:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97940#M20433</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-03-21T21:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97941#M20434</link>
      <description>&lt;P&gt;I managed to get it working without the DATETIME_CONFIG, although it is something that was causing an issue and I think I may raise a ticket to Splunk support unless anyone else has tried it and it works then the problem isnt with Splunk itself.&lt;/P&gt;

&lt;P&gt;The solution was to place the TZ = Australia/City and that worked like a Charm.&lt;/P&gt;

&lt;P&gt;Thanks Though&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2012 22:15:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97941#M20434</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-03-25T22:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97942#M20435</link>
      <description>&lt;P&gt;The solution was to place the TZ = Australia/City in props.conf and it worked like a Charm.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2012 22:16:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97942#M20435</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-03-25T22:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97943#M20436</link>
      <description>&lt;P&gt;This was kicking my butt. Thank you my friend.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 19:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97943#M20436</guid>
      <dc:creator>pipegrep</dc:creator>
      <dc:date>2015-10-09T19:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97944#M20437</link>
      <description>&lt;P&gt;Hey @Dark_Ichigo ,&lt;BR /&gt;
i guess i am also facing similar kind of issue, if you can help.&lt;BR /&gt;
I have log files, which is to be monitor on splunk. Those log files within them have the DATE Time constraints.&lt;BR /&gt;
Now when i am searching in search head, it is taking the time stamp from that log file. But my requirement was just to take the time, when the log file is created or last modified.&lt;/P&gt;

&lt;P&gt;I got the solution to set DATETIME_CONFIG= none in props.conf. But i am restricted not to make that change.&lt;BR /&gt;
Do you have any idea on the same?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 08:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-issue/m-p/97944#M20437</guid>
      <dc:creator>sarvesh_11</dc:creator>
      <dc:date>2019-04-02T08:00:22Z</dc:date>
    </item>
  </channel>
</rss>

