<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what can be done to keep the past in the past? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331117#M162572</link>
    <description>&lt;P&gt;Thanks for your reply, but here the issue is not related to re-indexing. &lt;/P&gt;

&lt;P&gt;My bad, may be I should have put more information. &lt;/P&gt;

&lt;P&gt;Example : &lt;/P&gt;

&lt;P&gt;we have some server X , Y &lt;/P&gt;

&lt;P&gt;and these 2 servers have log files with year old data. &lt;/P&gt;

&lt;P&gt;I installed the fwd and start getting logs from these 2 machines.  Now the issue is the logs which is already associated with old or last year time stamps when indexed In spunk will take current time. &lt;/P&gt;

&lt;P&gt;example : &lt;/P&gt;

&lt;P&gt;event 03/06/017 xyzzy .......... login attempt. &lt;/P&gt;

&lt;P&gt;during the index time it will take the current time not the actual event time.&lt;/P&gt;

&lt;P&gt;So do we have any way of these types of events already indexed we can setup the indexed time same as event time ?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Mar 2018 07:13:00 GMT</pubDate>
    <dc:creator>raomu</dc:creator>
    <dc:date>2018-03-06T07:13:00Z</dc:date>
    <item>
      <title>what can be done to keep the past in the past?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331113#M162568</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;For the past couple of weeks, we’ve seen events from the past being recently indexed. I assume that these few of the boxes were just powered up, and because of the forwarding infrastructure, that these are “current” events? &lt;BR /&gt;
what can be done to keep the past in the past?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 03:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331113#M162568</guid>
      <dc:creator>raomu</dc:creator>
      <dc:date>2018-03-06T03:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: what can be done to keep the past in the past?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331114#M162569</link>
      <description>&lt;P&gt;Hi, do you have a single source from where data is coming or multiple sources?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 05:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331114#M162569</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-03-06T05:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: what can be done to keep the past in the past?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331115#M162570</link>
      <description>&lt;P&gt;single source.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 06:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331115#M162570</guid>
      <dc:creator>raomu</dc:creator>
      <dc:date>2018-03-06T06:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: what can be done to keep the past in the past?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331116#M162571</link>
      <description>&lt;P&gt;Hi, If you have used &lt;CODE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/CODE&gt; from your &lt;CODE&gt;inputs.conf&lt;/CODE&gt; then you should remove that if you your files get rotated after a certain time duration. Setting &lt;CODE&gt;crcSalt&lt;/CODE&gt; in such case will cause re-indexing of your data.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 07:02:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331116#M162571</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-03-06T07:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: what can be done to keep the past in the past?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331117#M162572</link>
      <description>&lt;P&gt;Thanks for your reply, but here the issue is not related to re-indexing. &lt;/P&gt;

&lt;P&gt;My bad, may be I should have put more information. &lt;/P&gt;

&lt;P&gt;Example : &lt;/P&gt;

&lt;P&gt;we have some server X , Y &lt;/P&gt;

&lt;P&gt;and these 2 servers have log files with year old data. &lt;/P&gt;

&lt;P&gt;I installed the fwd and start getting logs from these 2 machines.  Now the issue is the logs which is already associated with old or last year time stamps when indexed In spunk will take current time. &lt;/P&gt;

&lt;P&gt;example : &lt;/P&gt;

&lt;P&gt;event 03/06/017 xyzzy .......... login attempt. &lt;/P&gt;

&lt;P&gt;during the index time it will take the current time not the actual event time.&lt;/P&gt;

&lt;P&gt;So do we have any way of these types of events already indexed we can setup the indexed time same as event time ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 07:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331117#M162572</guid>
      <dc:creator>raomu</dc:creator>
      <dc:date>2018-03-06T07:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: what can be done to keep the past in the past?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331118#M162573</link>
      <description>&lt;P&gt;Hi @raomu,&lt;/P&gt;

&lt;P&gt;You can keep the configuration &lt;CODE&gt;DATETIME_CONFIG =&lt;/CODE&gt; blank in props.conf instead of setting it to &lt;CODE&gt;CURRENT&lt;/CODE&gt; or &lt;CODE&gt;NONE&lt;/CODE&gt; that will consider the timestamp of the event.&lt;/P&gt;

&lt;P&gt;For your reference &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Propsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks. Let me know if that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 07:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-can-be-done-to-keep-the-past-in-the-past/m-p/331118#M162573</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-03-06T07:30:21Z</dc:date>
    </item>
  </channel>
</rss>

