<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: datetime.xml 2020 in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469407#M45687</link>
    <description>&lt;P&gt;@riqbal47010 &lt;/P&gt;

&lt;P&gt;have you check this?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=tIcRvw2zx34"&gt;https://www.youtube.com/watch?v=tIcRvw2zx34&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Check step 5 in &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020#Validate_timestamp_extraction_after_an_update"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020#Validate_timestamp_extraction_after_an_update&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Using the Splunk CLI, add the text file you saved earlier as a oneshot monitor to the Splunk platform instance that you want to validate.

$SPLUNK_HOME/bin/splunk add oneshot -source test_file.csv -sourcetype csv -index main
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 24 Dec 2019 07:07:55 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2019-12-24T07:07:55Z</dc:date>
    <item>
      <title>datetime.xml 2020</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469406#M45686</link>
      <description>&lt;P&gt;I am implemented the datetime.xml issue. Now according to article &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/FixDatetimexml2020"&gt;https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/FixDatetimexml2020&lt;/A&gt; &lt;BR /&gt;
I want to validate the change. &lt;/P&gt;

&lt;P&gt;I create test.csv file as metioned in above link. now how can I upload and validate in my distributed environment.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 06:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469406#M45686</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2019-12-24T06:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: datetime.xml 2020</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469407#M45687</link>
      <description>&lt;P&gt;@riqbal47010 &lt;/P&gt;

&lt;P&gt;have you check this?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=tIcRvw2zx34"&gt;https://www.youtube.com/watch?v=tIcRvw2zx34&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Check step 5 in &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020#Validate_timestamp_extraction_after_an_update"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020#Validate_timestamp_extraction_after_an_update&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Using the Splunk CLI, add the text file you saved earlier as a oneshot monitor to the Splunk platform instance that you want to validate.

$SPLUNK_HOME/bin/splunk add oneshot -source test_file.csv -sourcetype csv -index main
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Dec 2019 07:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469407#M45687</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-12-24T07:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: datetime.xml 2020</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469408#M45688</link>
      <description>&lt;P&gt;I gone through all the steps but I have distributed environment.&lt;BR /&gt;
below are performed steps.&lt;/P&gt;

&lt;P&gt;following step#3&lt;BR /&gt;
On Heavy forwarder I create props.conf file under $SPLUNK_HOME/etc/system/local&lt;BR /&gt;
[default]&lt;BR /&gt;
MAX_DAYS_HENCE = 40&lt;/P&gt;

&lt;P&gt;after that I add file through step#5&lt;/P&gt;

&lt;P&gt;but results are not as expected.&lt;/P&gt;

&lt;P&gt;the events time is the time when I am uploading the events.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:26:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469408#M45688</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2020-09-30T03:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: datetime.xml 2020</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469409#M45689</link>
      <description>&lt;P&gt;Did you executed step 4??&lt;/P&gt;

&lt;P&gt;Just for troubleshooting, is it possible to keep local copy in the HF and execute step 5 again. And just check data on HF only.&lt;/P&gt;

&lt;P&gt;I found steps For  distributed environment please check below link.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://blog.zivaro.com/splunk-product-timestamp-issue-solution"&gt;https://blog.zivaro.com/splunk-product-timestamp-issue-solution&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 10:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469409#M45689</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-12-24T10:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: datetime.xml 2020</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469410#M45690</link>
      <description>&lt;P&gt;hi kamlesh,&lt;/P&gt;

&lt;P&gt;thanks fory your kind support.&lt;/P&gt;

&lt;P&gt;I check the video link and found that to see the future date I have to select all times&lt;/P&gt;

&lt;P&gt;thanks for your support&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 13:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/datetime-xml-2020/m-p/469410#M45690</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2019-12-25T13:06:31Z</dc:date>
    </item>
  </channel>
</rss>

