Is there a document or configuration file that spells out all of the accepted default time formats on input. In other words, what are ALL the date/time formats that are accepted if I do not specify a format string in props.conf?
You really should specify TIME_FORMAT in props.conf for all your sourcetypes. It's a Splunk Best Practice.
Default time formats are in $SPLUNK_HOME/etc/datetime.xml.
View solution in original post