<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: time stamp mismatch in csv files in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512421#M4389</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Thanks for your quick reply, but I have already configure the current time, but still the same issue&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gowtham08091_0-1596561375127.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10037i440301279FA26616/image-size/medium?v=v2&amp;amp;px=400" role="button" title="gowtham08091_0-1596561375127.png" alt="gowtham08091_0-1596561375127.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 17:40:35 GMT</pubDate>
    <dc:creator>gowtham08091</dc:creator>
    <dc:date>2020-08-04T17:40:35Z</dc:date>
    <item>
      <title>time stamp mismatch in csv files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512415#M4386</link>
      <description>&lt;P&gt;I have a set if CSV files getting created every day, none of the CSV files have any default data or time printed within it, when i index the files i could see the data is getting index with different time stamps over the past date.&lt;/P&gt;&lt;P&gt;I have also used crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;Soucettype is CSV and set to Current,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;But all the file has created date and last modified data is the same (example today's date.) but the data gets indexed with different timestamp&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gowtham08091_0-1596560357505.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10036iD9EEB449FFF5B1D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="gowtham08091_0-1596560357505.png" alt="gowtham08091_0-1596560357505.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512415#M4386</guid>
      <dc:creator>gowtham08091</dc:creator>
      <dc:date>2020-08-04T17:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: time stamp mismatch in csv files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512416#M4387</link>
      <description>&lt;P&gt;Splunk is trying to find timestamp information in those files even if it doesn't exist. If you know your data does not have a timestamp in it you can tell Splunk that by putting&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DATETIME_CONFIG = current&lt;/LI-CODE&gt;&lt;P&gt;in the appropriate stanza of the props.conf file.&amp;nbsp; This props file must be installed on the first Splunk instance that parses the data - either a heavy forwarder or an indexer.&amp;nbsp; Be sure to restart the instance(s) after modifying the file.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512416#M4387</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-04T17:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: time stamp mismatch in csv files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512421#M4389</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Thanks for your quick reply, but I have already configure the current time, but still the same issue&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gowtham08091_0-1596561375127.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10037i440301279FA26616/image-size/medium?v=v2&amp;amp;px=400" role="button" title="gowtham08091_0-1596561375127.png" alt="gowtham08091_0-1596561375127.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/time-stamp-mismatch-in-csv-files/m-p/512421#M4389</guid>
      <dc:creator>gowtham08091</dc:creator>
      <dc:date>2020-08-04T17:40:35Z</dc:date>
    </item>
  </channel>
</rss>

