<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to change timestamp value on old data in an index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619880#M215450</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to add the same fixed one for every event within the file which will be uploaded.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 13:12:29 GMT</pubDate>
    <dc:creator>vishalduttauk</dc:creator>
    <dc:date>2022-11-07T13:12:29Z</dc:date>
    <item>
      <title>How to change timestamp value on old data in an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619822#M215414</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;I have a requirement where I have a large number of events which was uploaded on the 4th November but that needs to be changed to 1st November after it has been indexed. Is that possible?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619822#M215414</guid>
      <dc:creator>vishalduttauk</dc:creator>
      <dc:date>2022-11-08T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619834#M215422</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228513"&gt;@vishalduttauk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;indexed events cannot be modified, the only way is do delete them and reindiex with the correct timestamp.&lt;/P&gt;&lt;P&gt;Rememeber that devent deletion is only logical, not physical.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:21:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619834#M215422</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-07T10:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619867#M215442</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will do that. I can't rely on the created date of the file which i will re-upload? How can i specify the the timestamp as I have older data which needs to be uploaded.&lt;/P&gt;&lt;P&gt;The method is to use the add data functionality and to upload the txt file to the specified index.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 11:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619867#M215442</guid>
      <dc:creator>vishalduttauk</dc:creator>
      <dc:date>2022-11-07T11:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619873#M215445</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228513"&gt;@vishalduttauk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only one information: do you want to use a timestamp contained in the events or to add a fixed one?&lt;/P&gt;&lt;P&gt;if the timestamp is contained in the event, you have only to configure your timestamp recognition to read the correct timestamp from the events.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 12:43:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619873#M215445</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-07T12:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619880#M215450</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to add the same fixed one for every event within the file which will be uploaded.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 13:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619880#M215450</guid>
      <dc:creator>vishalduttauk</dc:creator>
      <dc:date>2022-11-07T13:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619883#M215451</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228513"&gt;@vishalduttauk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this isn't a usual approach, anyway, you could insert the date you want in the filename, then you could add to your&amp;nbsp;&lt;SPAN&gt;$SPLUNK_HOME/etc/datetime.xml the following raw:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;![CDATA[(?:^|source::).*?_(0?[1-9]|1[012])-(0?[1-9]|[12]\d|3[01])-(20\d\d|19\d\d|[901]\d(?!\d))\.log]]&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;remembering to rename your file as:&amp;nbsp;mylogs_11-&lt;SPAN&gt;1-2012.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 13:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/619883#M215451</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-07T13:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/620247#M215607</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am implementing that to the existing datetime.xml file. Is this what i should add?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;/define&amp;gt;&lt;BR /&gt;&amp;lt;define name="_masheddate2" extract="month, day, year"&amp;gt;&lt;BR /&gt;&amp;lt;text&amp;gt;&amp;lt;![CDATA[(?:^|mylogs_01-10-2022.log::).*?_(0?[1-9]|1[012])-(0?[1-9]|[12]\d|3[01])-(20\d\d|19\d\d|[901]\d(?!\d))\.log]]&amp;gt;&amp;lt;/text&amp;gt;&lt;BR /&gt;&amp;lt;/define&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 10:54:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/620247#M215607</guid>
      <dc:creator>vishalduttauk</dc:creator>
      <dc:date>2022-11-09T10:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to change timestamp value on old data in an index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/620256#M215611</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228513"&gt;@vishalduttauk&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"mylogs_01-10-2022.log" is a fixed string and you should use the field containing the field name, I suppose that your file name will change, so you have to use "source" instead "mylogs_01-10-2022.log".&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;define name="_masheddate2" extract="month, day, year"&amp;gt;
   &amp;lt;text&amp;gt;
      &amp;lt;![CDATA[(?:^|source::).*?_(0?[1-9]|1[012])-(0?[1-9]|[12]\d|3[01])-(20\d\d|19\d\d|[901]\d(?!\d))\.log]]&amp;gt;
   &amp;lt;/text&amp;gt;
&amp;lt;/define&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;It's important that you use this format ("string_dd-mm-yyyy.log") in the filename, otherwise, you have to change the regex.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in the first row you said "month, day, year", instead you have "day, month, year", you have to correct it based on the format you want to use in the file name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 11:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-timestamp-value-on-old-data-in-an-index/m-p/620256#M215611</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-09T11:50:03Z</dc:date>
    </item>
  </channel>
</rss>

