Dashboards & Visualizations

How do I verify that the datetime.xml file is applied?

spl109
Explorer

hi

After applying the FixDatetimexml2020 patch.
How do I verify that the datetime.xml file is applied?

For example
After setting multithreaded => singlethreaded

    ./splunk cmd btool  limits list | grep phased_execution_mode

As confirmed by the above method.

========================================================
안녕하세요.
FixDatetimexml2020 patch를 적용 후
datetime.xml이 적용이 잘 됐는지 어떻게 확인 할 수 있을까요?

예를들어
multithreaded => singlethreaded로 설정을 적용 한 후

./splunk cmd btool limits list | grep phased_execution_mode

위 명령어로 확인 했듯이

Thank you

Tags (1)
1 Solution

richgalloway
SplunkTrust
SplunkTrust

To test the fix, try ingesting a file that contains the two-digit year "20". Use a test index, of course. You'll also need to set MAX_DAYS_HENCE in props.conf to a value that includes the date in the file (at least 30).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To test the fix, try ingesting a file that contains the two-digit year "20". Use a test index, of course. You'll also need to set MAX_DAYS_HENCE in props.conf to a value that includes the date in the file (at least 30).

---
If this reply helps you, Karma would be appreciated.
0 Karma

spl109
Explorer

Thank you for your answer.

We checked the patches.
I wanted to make sure it was applied well on the operating server.

I was wondering if there was any other way besides an integrity check message.

0 Karma

spl109
Explorer
0 Karma

Sukisen1981
Champion

probably you should get an message like this in tne monitoring console?

File Integrity checks found 1 files that did not match the system-provided manifest. Review the list of problems reported by the InstalledFileHashChecker in splunkd.log File Integrity Check View ; potentially restore files from installation media, change practices to avoid changing files, or work with support to identify the problem.
https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/FixDatetimexml2020

If you are asking how do we know that the patch has fixed the issue- wait till jan 2020 , I guess!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...