<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk props timestamp issue in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-props-timestamp-issue/m-p/557202#M158256</link>
    <description>&lt;P&gt;I would try looking at timestamp extraction configuration. Specifically MAX_DAYS_AGO and MAX_DIFF_SECS_AGO in &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf" target="_blank" rel="noopener"&gt;props.conf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It could be the case that Splunk thinks that your events are far in the past and therefore not indexing them.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 13:47:33 GMT</pubDate>
    <dc:creator>smurf</dc:creator>
    <dc:date>2021-06-25T13:47:33Z</dc:date>
    <item>
      <title>splunk props timestamp issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-props-timestamp-issue/m-p/557148#M158226</link>
      <description>&lt;P&gt;I have a CSV file with the below data, trying to push to Splunk.&lt;/P&gt;&lt;P&gt;Example -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thu JUN 24&amp;nbsp; 15:27:52 +08 2021,name1,address1,Thu&amp;nbsp; JUN25&amp;nbsp; 12:27:52&amp;nbsp; +08 2021,Active&lt;/P&gt;&lt;P&gt;Thu JUN 24&amp;nbsp; 15:27:52 +08 2021,name2,address2,Thu JUN 25&amp;nbsp; 03:65:52&amp;nbsp; +08 2021,Active&lt;/P&gt;&lt;P&gt;Thu JUN 24&amp;nbsp; 15:27:52 +08 2021,name3,address3,Thu JUN 25&amp;nbsp; 05:15:52&amp;nbsp; +08 2021,Active&lt;/P&gt;&lt;P&gt;Thu JUN 24&amp;nbsp; 15:27:52 +08 2021,name4,address4,Thu MAY26&amp;nbsp; 06:25:52&amp;nbsp; +08 2021,Active&lt;/P&gt;&lt;P&gt;Thu JUN 24&amp;nbsp; 15:27:52 +08 2021,name5,address5,Thu MAY26&amp;nbsp; 06:15:52&amp;nbsp; +08 2021,Active&lt;/P&gt;&lt;P&gt;Thu JUN 24&amp;nbsp; 15:27:52 +08 2021,name6,address6,Thu JAN14&amp;nbsp; 07:15:52&amp;nbsp; +08 2021,Active&lt;/P&gt;&lt;P&gt;props setting&lt;/P&gt;&lt;P&gt;in props using fourth field as timestamp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE= FALSE
FIELD_DELIMETER=,
HEADER_FIELD_DELIMETER=,
FIELD_NAMES=Time,names,address,creationtime,status
TIMESTAMP_FIELDS=creationtime
TZ=Asia/Singapore&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;by using the above props I can able to push only the latest date data, other events are missing in Splunk.&lt;/P&gt;&lt;P&gt;for example, I can see only JUN25th data. remaining events are missing.&lt;/P&gt;&lt;P&gt;Can someone explain, what might be the cause.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 09:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-props-timestamp-issue/m-p/557148#M158226</guid>
      <dc:creator>kirrusk</dc:creator>
      <dc:date>2021-06-25T09:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: splunk props timestamp issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-props-timestamp-issue/m-p/557202#M158256</link>
      <description>&lt;P&gt;I would try looking at timestamp extraction configuration. Specifically MAX_DAYS_AGO and MAX_DIFF_SECS_AGO in &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf" target="_blank" rel="noopener"&gt;props.conf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It could be the case that Splunk thinks that your events are far in the past and therefore not indexing them.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 13:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-props-timestamp-issue/m-p/557202#M158256</guid>
      <dc:creator>smurf</dc:creator>
      <dc:date>2021-06-25T13:47:33Z</dc:date>
    </item>
  </channel>
</rss>

