<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Event timestamp behavior is inconsistent when DATETIME_CONFIG = NONE in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Event-timestamp-behavior-is-inconsistent-when-DATETIME-CONFIG/m-p/491483#M194243</link>
    <description>&lt;P&gt;I want to use a file's modification timestamp as the Splunk timestamp for the events it contains.&lt;BR /&gt;
Accordingly, I've set "DATETIME_CONFIG = NONE" in props.conf for the sourcetype. This props.conf is distributed to the forwarder and indexers.. &lt;/P&gt;

&lt;P&gt;The files are read with a "monitor" input on the forwarder. &lt;BR /&gt;
Two different behaviors;&lt;BR /&gt;
i) If Splunk on the forwarder is "not running" when the file is written, the file's events are timestamped as expected: i.e. the timestamp of the event matches the Modify time as reported by "stat" on the file.&lt;/P&gt;

&lt;P&gt;ii) However, if Splunk is "running" when the file is written, the file's events are timestamped using "change time" of the input file.&lt;/P&gt;

&lt;P&gt;Please advise how I can ensure that a file's events are always timestamped according to the file's modification time, regardless of whether the Splunk forwarder is running at the time the file is written.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jan 2020 22:43:26 GMT</pubDate>
    <dc:creator>sylim_splunk</dc:creator>
    <dc:date>2020-01-24T22:43:26Z</dc:date>
    <item>
      <title>Event timestamp behavior is inconsistent when DATETIME_CONFIG = NONE</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Event-timestamp-behavior-is-inconsistent-when-DATETIME-CONFIG/m-p/491483#M194243</link>
      <description>&lt;P&gt;I want to use a file's modification timestamp as the Splunk timestamp for the events it contains.&lt;BR /&gt;
Accordingly, I've set "DATETIME_CONFIG = NONE" in props.conf for the sourcetype. This props.conf is distributed to the forwarder and indexers.. &lt;/P&gt;

&lt;P&gt;The files are read with a "monitor" input on the forwarder. &lt;BR /&gt;
Two different behaviors;&lt;BR /&gt;
i) If Splunk on the forwarder is "not running" when the file is written, the file's events are timestamped as expected: i.e. the timestamp of the event matches the Modify time as reported by "stat" on the file.&lt;/P&gt;

&lt;P&gt;ii) However, if Splunk is "running" when the file is written, the file's events are timestamped using "change time" of the input file.&lt;/P&gt;

&lt;P&gt;Please advise how I can ensure that a file's events are always timestamped according to the file's modification time, regardless of whether the Splunk forwarder is running at the time the file is written.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 22:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Event-timestamp-behavior-is-inconsistent-when-DATETIME-CONFIG/m-p/491483#M194243</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2020-01-24T22:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Event timestamp behavior is inconsistent when DATETIME_CONFIG = NONE</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Event-timestamp-behavior-is-inconsistent-when-DATETIME-CONFIG/m-p/491484#M194244</link>
      <description>&lt;P&gt;This appears to be caused by Kernel bugs as this has been reproduced constantly with Splunk version 7.2.4.2 and Linux, 3.10.0-957.12.1.el7.x86_64. Now with the latest version as of this writing, 3.10.0-1062.4.1.el7.x86_64 it works fine as described in the splunk doc.  &lt;/P&gt;

&lt;P&gt;It's been always reproduced with Ubuntu 16.04.1 but not with Ubuntu 16.04.5 - whoever sees this issue it'd be worth while to upgrade the OS kernel.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:48:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Event-timestamp-behavior-is-inconsistent-when-DATETIME-CONFIG/m-p/491484#M194244</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2020-09-30T03:48:59Z</dc:date>
    </item>
  </channel>
</rss>

