<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to add a custom year for a certain file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-custom-year-for-a-certain-file/m-p/435882#M76060</link>
    <description>&lt;P&gt;I am using Spunk Enterprise to upload log files and generate a timeline.  I am uploading a linux secure.log file.  It has a date and time stamp, but is missing the year.  Splunk is automatically assigning the year 2018.  I want to manually set the year to 2017 for just this one log file - not other files.  Is there a way to automatically assign the year 2017, but keep the rest of date on the "Set Sourcetype" screen? Apparently you can edit props.conf, but I don't know if that will affect other files too. &lt;/P&gt;</description>
    <pubDate>Tue, 16 Oct 2018 20:27:03 GMT</pubDate>
    <dc:creator>mikemichaleson</dc:creator>
    <dc:date>2018-10-16T20:27:03Z</dc:date>
    <item>
      <title>How to add a custom year for a certain file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-custom-year-for-a-certain-file/m-p/435882#M76060</link>
      <description>&lt;P&gt;I am using Spunk Enterprise to upload log files and generate a timeline.  I am uploading a linux secure.log file.  It has a date and time stamp, but is missing the year.  Splunk is automatically assigning the year 2018.  I want to manually set the year to 2017 for just this one log file - not other files.  Is there a way to automatically assign the year 2017, but keep the rest of date on the "Set Sourcetype" screen? Apparently you can edit props.conf, but I don't know if that will affect other files too. &lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 20:27:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-a-custom-year-for-a-certain-file/m-p/435882#M76060</guid>
      <dc:creator>mikemichaleson</dc:creator>
      <dc:date>2018-10-16T20:27:03Z</dc:date>
    </item>
  </channel>
</rss>

