<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timestamp is not recognized in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-is-not-recognized/m-p/460804#M99475</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8952i770088B0C00BA79A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Use splunk enterprise version 7.2.3，Use the field to extract the timestamp, the time closer to the present can be identified, and the historical time cannot be identified, how to solve&lt;/P&gt;

&lt;P&gt;help！help&lt;/P&gt;</description>
    <pubDate>Thu, 21 May 2020 02:22:14 GMT</pubDate>
    <dc:creator>zhou51</dc:creator>
    <dc:date>2020-05-21T02:22:14Z</dc:date>
    <item>
      <title>Timestamp is not recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-is-not-recognized/m-p/460804#M99475</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8952i770088B0C00BA79A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Use splunk enterprise version 7.2.3，Use the field to extract the timestamp, the time closer to the present can be identified, and the historical time cannot be identified, how to solve&lt;/P&gt;

&lt;P&gt;help！help&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 02:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-is-not-recognized/m-p/460804#M99475</guid>
      <dc:creator>zhou51</dc:creator>
      <dc:date>2020-05-21T02:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp is not recognized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-is-not-recognized/m-p/460805#M99476</link>
      <description>&lt;P&gt;what's &lt;CODE&gt;INDEXED_EXTRACTION&lt;/CODE&gt; in props.conf ?&lt;/P&gt;

&lt;P&gt;and you should fix indexes.conf&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;frozenTimePeriodInSecs = &amp;lt; nonnegative integer&amp;gt;&lt;BR /&gt;
* The number of seconds after which indexed data rolls to frozen.&lt;BR /&gt;
* If you do not specify a 'coldToFrozenScript', data is deleted when rolled to frozen.&lt;BR /&gt;
* NOTE: Every event in a bucket must be older than &lt;CODE&gt;frozenTimePeriodInSecs&lt;/CODE&gt;  seconds before the bucket rolls to frozen.&lt;BR /&gt;
* The highest legal value is 4294967295.&lt;BR /&gt;
* Default: 188697600 (6 years)&lt;/P&gt;

&lt;P&gt;reference: &lt;A href="https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf"&gt;https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 May 2020 23:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-is-not-recognized/m-p/460805#M99476</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-23T23:18:07Z</dc:date>
    </item>
  </channel>
</rss>

