<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic index future date events as today's date in _time in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/index-future-date-events-as-today-s-date-in-time/m-p/404243#M71783</link>
    <description>&lt;P&gt;I am getting a future timestamped event, but I want to index it as default time of index. i.e. at the time when it got indexed.&lt;/P&gt;

&lt;P&gt;Presently I have changed&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;MAX_DAYS_HENCE      = 0&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;in my props.conf. But I found out that the event having tomorrow's date are getting index with tomorrow's date instead of today's date. &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/273250-annotation-2019-07-23-150547.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Like today its 23 July, I am looking for any events after today to be indexed for time 23 July.  But in my case 24 July is taken as a valid date which should not be the case. &lt;/P&gt;

&lt;P&gt;Any other workaround would be appreciated. &lt;/P&gt;

&lt;P&gt;The source data is JSON response of API which I am indexing via python script and taking PED field as _time&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:26:11 GMT</pubDate>
    <dc:creator>ayush1906</dc:creator>
    <dc:date>2020-09-30T01:26:11Z</dc:date>
    <item>
      <title>index future date events as today's date in _time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/index-future-date-events-as-today-s-date-in-time/m-p/404243#M71783</link>
      <description>&lt;P&gt;I am getting a future timestamped event, but I want to index it as default time of index. i.e. at the time when it got indexed.&lt;/P&gt;

&lt;P&gt;Presently I have changed&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;MAX_DAYS_HENCE      = 0&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;in my props.conf. But I found out that the event having tomorrow's date are getting index with tomorrow's date instead of today's date. &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/273250-annotation-2019-07-23-150547.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Like today its 23 July, I am looking for any events after today to be indexed for time 23 July.  But in my case 24 July is taken as a valid date which should not be the case. &lt;/P&gt;

&lt;P&gt;Any other workaround would be appreciated. &lt;/P&gt;

&lt;P&gt;The source data is JSON response of API which I am indexing via python script and taking PED field as _time&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:26:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/index-future-date-events-as-today-s-date-in-time/m-p/404243#M71783</guid>
      <dc:creator>ayush1906</dc:creator>
      <dc:date>2020-09-30T01:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: index future date events as today's date in _time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/index-future-date-events-as-today-s-date-in-time/m-p/404244#M71784</link>
      <description>&lt;P&gt;in props.conf use:&lt;BR /&gt;
&lt;CODE&gt;DATETIME_CONFIG = CURRENT&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;read here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Configuretimestamprecognition#Timestamp_validity_attributes_and_their_impact_on_events"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/Configuretimestamprecognition#Timestamp_validity_attributes_and_their_impact_on_events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 11:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/index-future-date-events-as-today-s-date-in-time/m-p/404244#M71784</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-07-23T11:53:04Z</dc:date>
    </item>
  </channel>
</rss>

