<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with dates in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45825#M10926</link>
    <description>&lt;P&gt;Oooh  that  is   OLD. Sorry, I cant remember all that happened since then.&lt;/P&gt;

&lt;P&gt;Did you try the props.conf settings?&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
    <pubDate>Wed, 09 May 2012 19:05:44 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2012-05-09T19:05:44Z</dc:date>
    <item>
      <title>Problem with dates</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45822#M10923</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;I'm doing searches on the indexed events of the last minutes or hours, and I get no results.&lt;BR /&gt;
I see that the problem is that Splunk is generating events in 2011, when today's events.&lt;BR /&gt;
Where does this by taking that date? How I can make it work?&lt;BR /&gt;
I attached a picture to see the failure.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i46.tinypic.com/25frb6a.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;BR /&gt;
Kindest regards.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2012 14:27:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45822#M10923</guid>
      <dc:creator>jjcorral</dc:creator>
      <dc:date>2012-05-08T14:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with dates</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45823#M10924</link>
      <description>&lt;P&gt;Well, the problem is that it seems like Splunk mismatches the date portion by one position, i.e. your log has the format mm/dd/yy , but Splunk parses this wrong (uses the month for day and the year for month (if you have a en-US locale, hard to tell from the numbers))&lt;/P&gt;

&lt;P&gt;Does this happen for all logs indexed by Splunk?&lt;BR /&gt;
What is your system clock set to on the indexer? 2011?&lt;BR /&gt;
What are the values for &lt;CODE&gt;timestartpos&lt;/CODE&gt; and &lt;CODE&gt;timeendpos&lt;/CODE&gt; for this particular event (you'll find them in the 'show all fields')?&lt;/P&gt;

&lt;P&gt;You might have to specify this manually in props.conf, though I've never had to do that ever for winevt-logs.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog:Security]
TIME_FORMAT = %m/%d/%Y %I:%M:%S %p
MAX_TIMESTAMP_LOOKAHEAD = 20
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian &lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2012 16:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45823#M10924</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-08T16:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with dates</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45824#M10925</link>
      <description>&lt;P&gt;Thanks four your answer.&lt;/P&gt;

&lt;P&gt;I have and European date. dd/mm/yy&lt;/P&gt;

&lt;P&gt;If the data comes from WinEventLog:Security fails, if comes from windows_snare_syslog it´s ok.&lt;/P&gt;

&lt;P&gt;No, the clock on the indexer are sntp sync.&lt;/P&gt;

&lt;P&gt;I have no timestartpos and timeendpos, my Splunk version is old. The 3.8.4, but i can´t migrate it.&lt;/P&gt;

&lt;P&gt;Exactly it take thet date bad, today is (in european format) 09/05/2012 und splunk gets 09/12/11&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45824#M10925</guid>
      <dc:creator>jjcorral</dc:creator>
      <dc:date>2020-09-28T11:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with dates</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45825#M10926</link>
      <description>&lt;P&gt;Oooh  that  is   OLD. Sorry, I cant remember all that happened since then.&lt;/P&gt;

&lt;P&gt;Did you try the props.conf settings?&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2012 19:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-dates/m-p/45825#M10926</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-09T19:05:44Z</dc:date>
    </item>
  </channel>
</rss>

