<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add File Date Info to Monitored File Date in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42700#M7982</link>
    <description>&lt;P&gt;In most cases the file date will be the _indextime date field.  the file may be created and moved into the folder on different dates. the file may be created on 5/22 but not put in the folder till 5/23.  I would like all the events in the file to have the 5/22 origination date not the indexed date.  Thanks for the tip and I will use the _indextime unless anyone else has a suggestion.&lt;/P&gt;

&lt;P&gt;Thanks Ayn&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2013 16:34:49 GMT</pubDate>
    <dc:creator>hartfoml</dc:creator>
    <dc:date>2013-05-22T16:34:49Z</dc:date>
    <item>
      <title>Add File Date Info to Monitored File Date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42698#M7980</link>
      <description>&lt;P&gt;I have a folder that a user puts files in on a semi regular bases.  I monitor the folder for new files and put the items in the file into a separate index to use for search. I dedup the events before doing the search so that I don't search for any event twice even if the entry is put in the index twice because the event is in multiple files in the folder.  I would like to add the file date to each event in the file so that I know when an event was created. the date on the file is the creation date not the date of index.  &lt;/P&gt;

&lt;P&gt;How can I add the file date onto each event in the file that is being indexed?&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 15:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42698#M7980</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-05-22T15:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Add File Date Info to Monitored File Date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42699#M7981</link>
      <description>&lt;P&gt;If file date == index date, just use the field &lt;CODE&gt;_indextime&lt;/CODE&gt; which holds this information.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 16:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42699#M7981</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-22T16:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Add File Date Info to Monitored File Date</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42700#M7982</link>
      <description>&lt;P&gt;In most cases the file date will be the _indextime date field.  the file may be created and moved into the folder on different dates. the file may be created on 5/22 but not put in the folder till 5/23.  I would like all the events in the file to have the 5/22 origination date not the indexed date.  Thanks for the tip and I will use the _indextime unless anyone else has a suggestion.&lt;/P&gt;

&lt;P&gt;Thanks Ayn&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 16:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Add-File-Date-Info-to-Monitored-File-Date/m-p/42700#M7982</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-05-22T16:34:49Z</dc:date>
    </item>
  </channel>
</rss>

