<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do i get splunk to handle the year in timestamps dated before ~2006 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-get-splunk-to-handle-the-year-in-timestamps-dated/m-p/50171#M9538</link>
    <description>&lt;P&gt;Yes, your dates are being restricted by the default &lt;CODE&gt;MAX_DAYS_AGO&lt;/CODE&gt; setting in props.conf. The default is 2000 (days), which currently puts the limit at September of 2005.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Feb 2011 09:14:42 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2011-02-25T09:14:42Z</dc:date>
    <item>
      <title>How do i get splunk to handle the year in timestamps dated before ~2006</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-get-splunk-to-handle-the-year-in-timestamps-dated/m-p/50170#M9537</link>
      <description>&lt;P&gt;No matter what format I attempt to force upon historical timestamps:&lt;/P&gt;

&lt;P&gt;either&lt;/P&gt;

&lt;P&gt;Feb 11, 2004 01:23:45&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;P&gt;2004-02-11 01:23:45&lt;/P&gt;

&lt;P&gt;splunk ignores years that fall before 2006 while the rest of the timestamp is preserved.  The current year (2011) is substituted for years &amp;lt;= 2006. &lt;/P&gt;

&lt;P&gt;Is this a configurable parameter/range I'm missing?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2011 08:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-get-splunk-to-handle-the-year-in-timestamps-dated/m-p/50170#M9537</guid>
      <dc:creator>tylr</dc:creator>
      <dc:date>2011-02-25T08:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get splunk to handle the year in timestamps dated before ~2006</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-get-splunk-to-handle-the-year-in-timestamps-dated/m-p/50171#M9538</link>
      <description>&lt;P&gt;Yes, your dates are being restricted by the default &lt;CODE&gt;MAX_DAYS_AGO&lt;/CODE&gt; setting in props.conf. The default is 2000 (days), which currently puts the limit at September of 2005.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2011 09:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-get-splunk-to-handle-the-year-in-timestamps-dated/m-p/50171#M9538</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-02-25T09:14:42Z</dc:date>
    </item>
  </channel>
</rss>

