<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk - TimeStamp Recognition Update in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500878#M46126</link>
    <description>&lt;P&gt;It is restart splunk service. No system/server reboot is required.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2019 06:48:25 GMT</pubDate>
    <dc:creator>manjunathmeti</dc:creator>
    <dc:date>2019-12-05T06:48:25Z</dc:date>
    <item>
      <title>Splunk - TimeStamp Recognition Update</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500875#M46123</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have got the  following requirement.&lt;/P&gt;

&lt;P&gt;We have identified a time-sensitive issue that affects all current versions of Splunk Enterprise, Splunk Light and Splunk Cloud. This issue has potential significant impact on data ingestion - including causing inaccurate, unsearchable, or prematurely-deleted data - starting January 1, 2020, when timestamps using two-digit years will stop being correctly recognized. Full details around this issue, including workarounds and product fixes, are documented in the Release Notes for each Splunk Version. &lt;/P&gt;

&lt;P&gt;Fix &amp;amp; Workarounds Available &lt;/P&gt;

&lt;P&gt;Splunk Cloud instances will be automatically upgraded prior to January 1, 2020. A support representative will advise you when the upgrade will take place. All Splunk Enterprise and Splunk Light customers, and any Splunk Cloud customers must apply one of the following changes to their Splunk Instance/s prior to January 1, 2020 to avoid the issue: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;PRE&gt;&lt;CODE&gt;  Download an updated version of datetime.xml and apply it to each of your Splunk platform instances
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;PRE&gt;&lt;CODE&gt;  Download and deploy an app to temporarily replace the defective datetime.xml with the fixed one
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;PRE&gt;&lt;CODE&gt;  Make modifications to existing datetime.xml on your Splunk platform instances
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;PRE&gt;&lt;CODE&gt;  Upgrade Splunk platform instances to a version with an updated version of datetime.xml
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Where from can we download the datetime.xml file.&lt;/P&gt;

&lt;P&gt;What is the path where datatime.xml file resides in the server.&lt;/P&gt;

&lt;P&gt;What is the path in the server where we can upload the downloaded datetime.xml file.&lt;/P&gt;

&lt;P&gt;What modifications we need to do once we upload the datetime.xml file&lt;/P&gt;

&lt;P&gt;How to upgrade Splunk platform instance to a version with an updated version of datetime.xml.&lt;/P&gt;

&lt;P&gt;On which servers we need to upload the datetime.xml. &lt;BR /&gt;
Splunk Forwarder&lt;BR /&gt;
Splunk Indexer&lt;BR /&gt;
Splunk License server.&lt;/P&gt;

&lt;P&gt;Is a reboot of the server required after the upgrade or if we restart splunk services it is enough.&lt;/P&gt;

&lt;P&gt;It would be great  if you could provide the steps to perform the above activity.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Pratapa.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 10:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500875#M46123</guid>
      <dc:creator>pratapa</dc:creator>
      <dc:date>2019-12-04T10:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - TimeStamp Recognition Update</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500876#M46124</link>
      <description>&lt;P&gt;You can find answers here for all your questions here: &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 14:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500876#M46124</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2019-12-04T14:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - TimeStamp Recognition Update</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500877#M46125</link>
      <description>&lt;P&gt;In the above doc. It is mentioned that need to restart splunk platform.&lt;/P&gt;

&lt;P&gt;Question is shall we restart the service or restart the server?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 06:21:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500877#M46125</guid>
      <dc:creator>jibin1988</dc:creator>
      <dc:date>2019-12-05T06:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - TimeStamp Recognition Update</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500878#M46126</link>
      <description>&lt;P&gt;It is restart splunk service. No system/server reboot is required.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 06:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500878#M46126</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2019-12-05T06:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - TimeStamp Recognition Update</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500879#M46127</link>
      <description>&lt;P&gt;Where from can we download the datetime.xml file.&lt;/P&gt;

&lt;P&gt;Link :&lt;A href="https://download.splunk.com/products/ingest2020/datetime.zip"&gt;https://download.splunk.com/products/ingest2020/datetime.zip&lt;/A&gt;&lt;BR /&gt;
&lt;STRONG&gt;You can use wget method for downloaind this XML File.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;What is the path where datatime.xml file resides in the server.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;/Opt/splunk/etc&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;What is the path in the server where we can upload the downloaded datetime.xml file.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I would like to recommend you to download the XML in /opt file path . Then you can move to /opt/splunk/etc. It will ask you to overwrite. Select Yes.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;What modifications we need to do once we upload the datetime.xml file&lt;BR /&gt;
&lt;STRONG&gt;You have to replace the existing datetime.xml file in /opt/splunk/etc&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;How to upgrade Splunk platform instance to a version with an updated version of datetime.xml.&lt;BR /&gt;
&lt;STRONG&gt;No need upgrade the splunk platform instance. This changes is enough.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;On which servers we need to upload the datetime.xml.&lt;BR /&gt;
Splunk Forwarder&lt;BR /&gt;
Splunk Indexer&lt;BR /&gt;
Splunk License server.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;On all the Splunk instance.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Is a reboot of the server required after the upgrade or if we restart splunk services it is enough.&lt;BR /&gt;
&lt;STRONG&gt;Restarting the splunk service is more enough.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 07:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500879#M46127</guid>
      <dc:creator>kartm2020</dc:creator>
      <dc:date>2019-12-05T07:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk - TimeStamp Recognition Update</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500880#M46128</link>
      <description>&lt;P&gt;How Can we do it in all the universal forwarders? I have already done this in indexer,deployments server/license master, heavy forwarders, search heads.&lt;/P&gt;

&lt;P&gt;We have like 1000 hosts reporting to splunk, How Can I do this manually on all uf?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 16:01:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-TimeStamp-Recognition-Update/m-p/500880#M46128</guid>
      <dc:creator>sandeepghi</dc:creator>
      <dc:date>2019-12-23T16:01:52Z</dc:date>
    </item>
  </channel>
</rss>

