<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: setting the default date format for events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27672#M4658</link>
    <description>&lt;P&gt;It's better to do this with a TIME_FORMAT for each sourcetype, but otherwise you could create your own datetime.xml and then  use the default stanza  to specify using your copy of datetime.xml.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Nov 2012 16:21:42 GMT</pubDate>
    <dc:creator>dart</dc:creator>
    <dc:date>2012-11-08T16:21:42Z</dc:date>
    <item>
      <title>setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27668#M4654</link>
      <description>&lt;P&gt;I have a date in my input files 08-11-12, This date could be August 11. 2012, or (as is the case) November 8. 2012, as I use European date-format.&lt;/P&gt;

&lt;P&gt;It looks like Splunk likes to use the American date-format before using the European, so it thinks the event was written in august.&lt;/P&gt;

&lt;P&gt;How do I change the default behavior, so that it first uses European format, and then American?&lt;/P&gt;

&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 11:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27668#M4654</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2012-11-08T11:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27669#M4655</link>
      <description>&lt;P&gt;Check out the TIME_FORMAT parameter for props.conf. With that you specify how the incoming timestamps should be parsed.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27669#M4655</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-11-08T12:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27670#M4656</link>
      <description>&lt;P&gt;Yes, but isn't that on a sourcetype basis. I want to default use the European formats before the American.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27670#M4656</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2012-11-08T12:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27671#M4657</link>
      <description>&lt;P&gt;These issues are typically found on a per-sourcetype basis, so setting a global default is kind of dangerous. But, if you really know what you are doing you could set a global setting using the [default] stanza in props.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 13:57:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27671#M4657</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-11-08T13:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27672#M4658</link>
      <description>&lt;P&gt;It's better to do this with a TIME_FORMAT for each sourcetype, but otherwise you could create your own datetime.xml and then  use the default stanza  to specify using your copy of datetime.xml.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 16:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27672#M4658</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-11-08T16:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27673#M4659</link>
      <description>&lt;P&gt;Thanks - as usual very helpful info.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 11:38:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27673#M4659</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2012-11-09T11:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: setting the default date format for events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27674#M4660</link>
      <description>&lt;P&gt;I used the comment from dart.&lt;BR /&gt;
A little more work, but it works.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 11:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-the-default-date-format-for-events/m-p/27674#M4660</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2012-11-09T11:39:44Z</dc:date>
    </item>
  </channel>
</rss>

