<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error event time (one more year) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205397#M40542</link>
    <description>&lt;P&gt;Hi Rich!&lt;/P&gt;

&lt;P&gt;I have validated on MySQL command line and there we are the correct date and time of event (December 30, 2014). This is the correct data.&lt;/P&gt;

&lt;P&gt;On MySQL query inside splunk (befor index) the timestamp on DATA COLUMN its correct (December 30, 2014). The incorrect date is on search event, according to the images that I sent you.&lt;/P&gt;

&lt;P&gt;Please, take a look ate the  timeendpos and  timestartpos fields on files. The events with incorrect date, the timestartpos are ALWAYS 12 value. &lt;/P&gt;

&lt;P&gt;Please, take a look at the new image below:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://imageshack.com/a/img903/4308/1qoIWH.png"&gt;http://imageshack.com/a/img903/4308/1qoIWH.png&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;From 21.590 events, only 54 have incorrect date, that match with the timestartpos = 12 value. Do you understood? I hope this help us to troubleshooting.&lt;/P&gt;

&lt;P&gt;Thanks and regards! &lt;/P&gt;

&lt;P&gt;Luis Carlos&lt;BR /&gt;
Skype: lcb.lucas&lt;/P&gt;</description>
    <pubDate>Mon, 26 Oct 2015 16:38:44 GMT</pubDate>
    <dc:creator>lcblucas</dc:creator>
    <dc:date>2015-10-26T16:38:44Z</dc:date>
    <item>
      <title>Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205390#M40535</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;In DB Input of DB CONNECT, inside PARAMETERS, I configured to CHOOSE COLUMN on timestamp, instead default option (CURRENT INDEX TIME), and select my column that have a date. &lt;/P&gt;

&lt;P&gt;When I go on search page, any event are one more year. For example: The correct date of event is 29/12/2014, but the splunk event show 29/10/2015 (December of this year).&lt;/P&gt;

&lt;P&gt;Does anybody can help me, please?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2015 22:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205390#M40535</guid>
      <dc:creator>lcblucas</dc:creator>
      <dc:date>2015-10-25T22:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205391#M40536</link>
      <description>&lt;P&gt;Could you post one full row of your database as dbquery would display it?&lt;/P&gt;

&lt;P&gt;And also can you post one full event as Splunk has it?  It would be awesome if you could paste in the &lt;EM&gt;same&lt;/EM&gt; event/row!&lt;/P&gt;

&lt;P&gt;Then last, let us know which column you used as your time stamp column.  &lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 01:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205391#M40536</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-10-26T01:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205392#M40537</link>
      <description>&lt;P&gt;Hi Rich7177!&lt;/P&gt;

&lt;P&gt;Thanks for your attention! Below the image links for your requests:&lt;/P&gt;

&lt;P&gt;02 files (db query and event search) of incorrect date&lt;BR /&gt;
 - &lt;A href="http://imageshack.com/a/img908/4213/H77my6.png"&gt;http://imageshack.com/a/img908/4213/H77my6.png&lt;/A&gt;&lt;BR /&gt;
 - &lt;A href="http://imageshack.com/a/img911/7484/OWugur.png"&gt;http://imageshack.com/a/img911/7484/OWugur.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;02 files (db query and event search) of correct date&lt;BR /&gt;
 - &lt;A href="http://imagizer.imageshack.us/a/img903/6195/g8Sdtq.png"&gt;http://imagizer.imageshack.us/a/img903/6195/g8Sdtq.png&lt;/A&gt;&lt;BR /&gt;
 - &lt;A href="http://imageshack.com/a/img908/1958/ty4va3.png"&gt;http://imageshack.com/a/img908/1958/ty4va3.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;01 file of "set parameters" inside DB Ipunt configuration.&lt;BR /&gt;
- &lt;A href="http://imageshack.com/a/img910/7704/JD28WZ.png"&gt;http://imageshack.com/a/img910/7704/JD28WZ.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Let me know if you need another data.&lt;/P&gt;

&lt;P&gt;Thanks again for your attention!&lt;/P&gt;

&lt;P&gt;Luis Carlos&lt;BR /&gt;
Skype: lcb.lucas&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 14:51:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205392#M40537</guid>
      <dc:creator>lcblucas</dc:creator>
      <dc:date>2015-10-26T14:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205393#M40538</link>
      <description>&lt;P&gt;In your example 02 incorrect, second image: that date at the front of the event is in the future - this is the issue?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 15:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205393#M40538</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-10-26T15:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205394#M40539</link>
      <description>&lt;P&gt;Given the screenshots, it appears your source database has those "wrong" dates in it.  Splunk is using the date/time when it's valid (which means it is not newer than two days in the future by default).  When that date falls farther in the future than two days from now (a default you can change if required) it instead uses the current date/time as the timestamp.&lt;/P&gt;

&lt;P&gt;So, if those are actually correct and you want them to show up as December 30th 2015, you can likely adjust your timestamp recognition to allow a bigger &lt;CODE&gt;MAX_DAYS_HENCE&lt;/CODE&gt; as &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Configuretimestamprecognition"&gt;documented here&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;If that data is wrong in the original DB (like if that should actually be December 30th, 2014 - or indeed any time in the past), then if you correct it in the original DB Splunk should be able to interpret it properly.&lt;/P&gt;

&lt;P&gt;Edit: Accidental premature "Post" before proofing and tweaking phrasing.  Then rephrased for clarity.  Sorry!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 15:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205394#M40539</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-10-26T15:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205395#M40540</link>
      <description>&lt;P&gt;yes. But only in a few events, not total of events.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 16:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205395#M40540</guid>
      <dc:creator>lcblucas</dc:creator>
      <dc:date>2015-10-26T16:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205396#M40541</link>
      <description>&lt;P&gt;Right.  See answer below.  Are you the DBA responsible for the DB itself, or is someone else in that role?  From the information you've supplied, there appears to be bad data &lt;EM&gt;inside&lt;/EM&gt; the database.  Splunk will read a timestamp up to two days in the future by default, if it's farther ahead than 2 days it doesn't use that timestamp and instead uses the &lt;STRONG&gt;current&lt;/STRONG&gt; time as of when it ingested that data.&lt;/P&gt;

&lt;P&gt;If that data is correct and it's REALLY supposed to be 2 months in the future, I outline what to look for to fix it so Splunk will read that correctly.&lt;/P&gt;

&lt;P&gt;If that data is incorrect in the original DB, then it should be fixed there.  Splunk isn't doing anything wrong, the original DB is wrong so is giving Splunk the wrong information.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 16:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205396#M40541</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-10-26T16:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205397#M40542</link>
      <description>&lt;P&gt;Hi Rich!&lt;/P&gt;

&lt;P&gt;I have validated on MySQL command line and there we are the correct date and time of event (December 30, 2014). This is the correct data.&lt;/P&gt;

&lt;P&gt;On MySQL query inside splunk (befor index) the timestamp on DATA COLUMN its correct (December 30, 2014). The incorrect date is on search event, according to the images that I sent you.&lt;/P&gt;

&lt;P&gt;Please, take a look ate the  timeendpos and  timestartpos fields on files. The events with incorrect date, the timestartpos are ALWAYS 12 value. &lt;/P&gt;

&lt;P&gt;Please, take a look at the new image below:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://imageshack.com/a/img903/4308/1qoIWH.png"&gt;http://imageshack.com/a/img903/4308/1qoIWH.png&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;From 21.590 events, only 54 have incorrect date, that match with the timestartpos = 12 value. Do you understood? I hope this help us to troubleshooting.&lt;/P&gt;

&lt;P&gt;Thanks and regards! &lt;/P&gt;

&lt;P&gt;Luis Carlos&lt;BR /&gt;
Skype: lcb.lucas&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 16:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205397#M40542</guid>
      <dc:creator>lcblucas</dc:creator>
      <dc:date>2015-10-26T16:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205398#M40543</link>
      <description>&lt;P&gt;Hi Rich!&lt;/P&gt;

&lt;P&gt;I have validated on MySQL command line and there we are the correct date and time of event (December 30, 2014). This is the correct data.&lt;/P&gt;

&lt;P&gt;On MySQL query inside splunk (befor index) the timestamp on DATA COLUMN its correct (December 30, 2014). The incorrect date is on search event, according to the images that I sent you.&lt;/P&gt;

&lt;P&gt;Please, take a look ate the timeendpos and timestartpos fields on files. The events with incorrect date, the timestartpos are ALWAYS 12 value.&lt;/P&gt;

&lt;P&gt;Please, take a look at the new image below:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://imageshack.com/a/img903/4308/1qoIWH.png"&gt;http://imageshack.com/a/img903/4308/1qoIWH.png&lt;/A&gt;&lt;BR /&gt;
From 21.590 events, only 54 have incorrect date, that match with the timestartpos = 12 value. Do you understood? I hope this help us to troubleshooting.&lt;/P&gt;

&lt;P&gt;Thanks and regards!&lt;/P&gt;

&lt;P&gt;Luis Carlos&lt;BR /&gt;
Skype: lcb.lucas&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 12:37:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205398#M40543</guid>
      <dc:creator>lcblucas</dc:creator>
      <dc:date>2015-10-27T12:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: Error event time (one more year)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205399#M40544</link>
      <description>&lt;P&gt;Please take a look at this post&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/235558/wrong-datetime-conversion-from-epoch.html"&gt;https://answers.splunk.com/answers/235558/wrong-datetime-conversion-from-epoch.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I believe it is probably the same issue....  (I cannot validate, as I cannot view the posted screenshots from here). &lt;BR /&gt;
I believe there is a bug in the splunk db connect app when converting epoch timestamps to human readable form. If left in epoch format, splunk indexes these without issue.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 14:47:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-event-time-one-more-year/m-p/205399#M40544</guid>
      <dc:creator>henchrm</dc:creator>
      <dc:date>2016-03-31T14:47:19Z</dc:date>
    </item>
  </channel>
</rss>

