<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timestamp recognition props.conf (event time using MM/DD/YYYY instead of DD/MM/YYYY in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178490#M35786</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
Every month 1st, I am facing the below issue.&lt;BR /&gt;
Splunk stopped indexing on 1st of every month&lt;BR /&gt;
For ex : Feb 1st it stopped indexing &amp;amp; it retrieved on 2nd, and on March 1st stopped and indexing again on 3rd march.&lt;BR /&gt;
Look like splunk recognizing logs as MM/DD though DD/MM in the log&lt;/P&gt;

&lt;P&gt;I tried to add "%d/%m/%Y %H:%M:%S" in props.conf but still no luck&lt;/P&gt;

&lt;P&gt;timestamp="09/04/2015 10:06:30",  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX, transactionstart="09/04/2015 10:06:30", transactionend="09/04/2015 10:06:30", &lt;/P&gt;

&lt;P&gt;Can some one suggest me what should I do?&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2015 13:26:59 GMT</pubDate>
    <dc:creator>marellasunil</dc:creator>
    <dc:date>2015-05-01T13:26:59Z</dc:date>
    <item>
      <title>Timestamp recognition props.conf (event time using MM/DD/YYYY instead of DD/MM/YYYY</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178490#M35786</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
Every month 1st, I am facing the below issue.&lt;BR /&gt;
Splunk stopped indexing on 1st of every month&lt;BR /&gt;
For ex : Feb 1st it stopped indexing &amp;amp; it retrieved on 2nd, and on March 1st stopped and indexing again on 3rd march.&lt;BR /&gt;
Look like splunk recognizing logs as MM/DD though DD/MM in the log&lt;/P&gt;

&lt;P&gt;I tried to add "%d/%m/%Y %H:%M:%S" in props.conf but still no luck&lt;/P&gt;

&lt;P&gt;timestamp="09/04/2015 10:06:30",  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX, transactionstart="09/04/2015 10:06:30", transactionend="09/04/2015 10:06:30", &lt;/P&gt;

&lt;P&gt;Can some one suggest me what should I do?&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 13:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178490#M35786</guid>
      <dc:creator>marellasunil</dc:creator>
      <dc:date>2015-05-01T13:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition props.conf (event time using MM/DD/YYYY instead of DD/MM/YYYY</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178491#M35787</link>
      <description>&lt;P&gt;What is the source of your data? is it from a forwarder? if yes, it may be a game of time zones.&lt;/P&gt;

&lt;P&gt;see&lt;/P&gt;

&lt;P&gt;docs.splunk.com/Documentation/Splunk/6.2.2/data/Applytimezoneoffsetstotimestamps&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 14:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178491#M35787</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-05-01T14:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition props.conf (event time using MM/DD/YYYY instead of DD/MM/YYYY</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178492#M35788</link>
      <description>&lt;P&gt;Hi Stephane,&lt;BR /&gt;
Thanks for the reply.&lt;BR /&gt;
Yes it is forwarder, even I have add the below stanza to props.conf file (In deployment server) which did not work, even changed in all indexers $SPLUNK_HOME$/system/local/props.conf as well&lt;/P&gt;

&lt;P&gt;[sourcetype_proj]&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TIME_FORMAT = %d/%m/%Y %H:%M:%S&lt;BR /&gt;
TIME_PREFIX = timestamp="&lt;BR /&gt;
TZ = Europe/London&lt;BR /&gt;
category = Custom&lt;BR /&gt;
pulldown_type = true&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition-props-conf-event-time-using-MM-DD-YYYY/m-p/178492#M35788</guid>
      <dc:creator>marellasunil</dc:creator>
      <dc:date>2020-09-28T19:48:42Z</dc:date>
    </item>
  </channel>
</rss>

