Archive
Highlighted

Issue with date and time for indexed csv data

Explorer

I am facing date time issue while indexing csv data .
I do have a date field in my CSV file but i want to consider system time for an indexed data. I have added below parameters into props.conf of windows UF and on single instance linux splunk server $splunk home$/etc/system/local props.conf but still it is taking date/ time from the csv file.
Please suggest.

DATETIMECONFIG = NONE
MAX
TIMESTAMP_LOOKAHEAD = 0

Tags (1)
0 Karma
Highlighted

Re: Issue with date and time for indexed csv data

Legend

@darshini2790 if you are planning to use current time, should you not be using?

   DATETIME_CONFIG = CURRENT 



| eval message="Happy Splunking!!!"


Highlighted

Re: Issue with date and time for indexed csv data

Explorer

Yes I have tried that as well and no luck.

0 Karma
Highlighted

Re: Issue with date and time for indexed csv data

SplunkTrust
SplunkTrust

Hi,

  1. MAXTIMESTAMPLOOKAHEAD should not be set to 0.
  2. DATETIME_CONFIG should not be set to "none" in your case.
  3. Did you set KV_MODE = none on your Search Head? The question is, if you want indexed extractions or not.

Skalli

View solution in original post