<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fix datetime.xml file in SPlunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500387#M139322</link>
    <description>&lt;P&gt;according to &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/ReleaseNotes/FixDatetimexml2020#Impact" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/ReleaseNotes/FixDatetimexml2020#Impact&lt;/A&gt; you need to patch UFs under the following known conditions:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;When they have been configured to process structured data, such as CSV, XML, and JSON files, using the INDEXED_EXTRACTIONS setting in props.conf&lt;/LI&gt;
&lt;LI&gt;When they have been configured to process data locally, using the force_local_processing setting in props.conf&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;if you don't local process on UF, you &lt;STRONG&gt;don't need to patch&lt;/STRONG&gt; them&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:42:53 GMT</pubDate>
    <dc:creator>PavelP</dc:creator>
    <dc:date>2020-09-30T04:42:53Z</dc:date>
    <item>
      <title>Fix datetime.xml file in SPlunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500385#M139320</link>
      <description>&lt;P&gt;So I have to update my datetime.xml file in Splunk because timestamp extraction problem after 1jan 2020.&lt;/P&gt;

&lt;P&gt;According to splunk we have to override new file provided from them to existing file.&lt;/P&gt;

&lt;P&gt;Now my question:&lt;BR /&gt;
I have 10I, 20SH, 2HF, 1000's of UF. &lt;BR /&gt;
Do i need to update datetime.xml on just my Heavy forwarders?&lt;BR /&gt;
Do i need to update new datetime.xml on all indexers as well? If yes, Please help me how to push configuration from master.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 01:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500385#M139320</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2020-03-26T01:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Fix datetime.xml file in SPlunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500386#M139321</link>
      <description>&lt;P&gt;@muizash yes, you will need to update the datetime xml on &lt;STRONG&gt;all&lt;/STRONG&gt; the Splunk endpoints. &lt;BR /&gt;
Option 1: Download the new datetime.xml and copy it to $SPLUNK_HOME/etc/. This will replace the exisiting datetime.xml file. After that you will need to restart the Splunk instance. Now this location cannot be touched by the deployment server, so you will need to push the files out using an alternative method on all your UF's.&lt;/P&gt;

&lt;P&gt;Option 2: Upgrade the Splunk version you're running across all instance. The new install has the updated datetime.xml file&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 05:44:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500386#M139321</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-03-26T05:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Fix datetime.xml file in SPlunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500387#M139322</link>
      <description>&lt;P&gt;according to &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/ReleaseNotes/FixDatetimexml2020#Impact" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/ReleaseNotes/FixDatetimexml2020#Impact&lt;/A&gt; you need to patch UFs under the following known conditions:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;When they have been configured to process structured data, such as CSV, XML, and JSON files, using the INDEXED_EXTRACTIONS setting in props.conf&lt;/LI&gt;
&lt;LI&gt;When they have been configured to process data locally, using the force_local_processing setting in props.conf&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;if you don't local process on UF, you &lt;STRONG&gt;don't need to patch&lt;/STRONG&gt; them&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fix-datetime-xml-file-in-SPlunk/m-p/500387#M139322</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-09-30T04:42:53Z</dc:date>
    </item>
  </channel>
</rss>

