All Apps and Add-ons

How to find events with invalid date prior to 1/1/1970?

mikelanghorst
Motivator

A few days ago I found a new sourcetype on the summary page of sourcetype=131228018 with 1.3B events and a last update of "12/31/1969 16:00:00"

I'm at a loss on how to find this data, I can't search for it in the interface. All Time returns no results, and it won't let you choose a date prior to 1/1/1970. Briefly looking at the indexes, I don't see any buckets with larger than expected spans.

How can I find these events so that I can correct and purge them?

1 Solution

mikelanghorst
Motivator

Just worked with Octavio down in the answers lab, with Vincent from PS, and found the issue with the help of the S.o.S. app they released.

The problem was corrupted metadata in the indexes, caused by a bug when the deploymentServer initiates a restart of the indexers. I'm currently in the process of cleaning up the data using "splunk cmd splunkd fsck".

View solution in original post

mikelanghorst
Motivator

Just worked with Octavio down in the answers lab, with Vincent from PS, and found the issue with the help of the S.o.S. app they released.

The problem was corrupted metadata in the indexes, caused by a bug when the deploymentServer initiates a restart of the indexers. I'm currently in the process of cleaning up the data using "splunk cmd splunkd fsck".

mzorzi
Splunk Employee
Splunk Employee

try this search with all the time:

index="*" sourcetype="*131228018*"

0 Karma

malberto
Explorer

When you search on "sourcetype=131228018" that should find it, if you're searching all time. If not, that's a bug.

0 Karma

mikelanghorst
Motivator

That's what I would expect as well, but returns 0 events. Currently have a case open with support, but figured I'd drop it out here as well.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...