<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Importing 'old' data set results in incorrect date extraction after 2010 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250340#M48173</link>
    <description>&lt;P&gt;You'll likely need to increase &lt;CODE&gt;MAX_DAYS_AGO&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MAX_DAYS_AGO = &amp;lt;integer&amp;gt;
* Specifies the maximum number of days past, from the current date, that an extracted date  can be valid.
* For example, if MAX_DAYS_AGO = 10, Splunk ignores dates that are older than 10 days ago.
* Defaults to 2000 (days), maximum 10951.
* IMPORTANT: If your data is older than 2000 days, increase this setting.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 25 Nov 2015 14:16:05 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-11-25T14:16:05Z</dc:date>
    <item>
      <title>Importing 'old' data set results in incorrect date extraction after 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250338#M48171</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Trying to import a CSV with dates going back 50+ years (&lt;A href="https://www.quandl.com/api/v3/datasets/BCB/UDJIAD1.csv"&gt;https://www.quandl.com/api/v3/datasets/BCB/UDJIAD1.csv&lt;/A&gt;).&lt;BR /&gt;
I have correctly set the props date extraction and it works, except for events after 2010. &lt;BR /&gt;
What's happened is all the "old" dates are now bunched up at 6/7/2010 and haven't extracted properly.&lt;/P&gt;

&lt;P&gt;I know their is quarantine settings for indexes.conf but that should still display the data correctly it just puts it into different buckets on disk.....&lt;/P&gt;

&lt;P&gt;Is there a limitation of how 'old' data you can import? How can I fix it?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ dow_jones_index_csv ]
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
KV_MODE=none
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
TIMESTAMP_FIELDS=Date
TIME_FORMAT=%Y-%m-%d
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 25 Nov 2015 10:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250338#M48171</guid>
      <dc:creator>cam343</dc:creator>
      <dc:date>2015-11-25T10:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Importing 'old' data set results in incorrect date extraction after 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250339#M48172</link>
      <description>&lt;P&gt;I tried increasing to: &lt;BR /&gt;
  frozenTimePeriodInSecs = 4294967295&lt;/P&gt;

&lt;P&gt;but it didnt make a difference....&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 11:35:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250339#M48172</guid>
      <dc:creator>cam343</dc:creator>
      <dc:date>2015-11-25T11:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Importing 'old' data set results in incorrect date extraction after 2010</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250340#M48173</link>
      <description>&lt;P&gt;You'll likely need to increase &lt;CODE&gt;MAX_DAYS_AGO&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MAX_DAYS_AGO = &amp;lt;integer&amp;gt;
* Specifies the maximum number of days past, from the current date, that an extracted date  can be valid.
* For example, if MAX_DAYS_AGO = 10, Splunk ignores dates that are older than 10 days ago.
* Defaults to 2000 (days), maximum 10951.
* IMPORTANT: If your data is older than 2000 days, increase this setting.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 25 Nov 2015 14:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Importing-old-data-set-results-in-incorrect-date-extraction/m-p/250340#M48173</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-11-25T14:16:05Z</dc:date>
    </item>
  </channel>
</rss>

