Dashboards & Visualizations

datetime.xml 2020

riqbal47010
Path Finder

I am implemented the datetime.xml issue. Now according to article
https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/FixDatetimexml2020
I want to validate the change.

I create test.csv file as metioned in above link. now how can I upload and validate in my distributed environment.

Tags (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@riqbal47010

have you check this?

https://www.youtube.com/watch?v=tIcRvw2zx34

Check step 5 in https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020#Validate_timestam...

Using the Splunk CLI, add the text file you saved earlier as a oneshot monitor to the Splunk platform instance that you want to validate.

$SPLUNK_HOME/bin/splunk add oneshot -source test_file.csv -sourcetype csv -index main

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@riqbal47010

have you check this?

https://www.youtube.com/watch?v=tIcRvw2zx34

Check step 5 in https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020#Validate_timestam...

Using the Splunk CLI, add the text file you saved earlier as a oneshot monitor to the Splunk platform instance that you want to validate.

$SPLUNK_HOME/bin/splunk add oneshot -source test_file.csv -sourcetype csv -index main
0 Karma

riqbal47010
Path Finder

I gone through all the steps but I have distributed environment.
below are performed steps.

following step#3
On Heavy forwarder I create props.conf file under $SPLUNK_HOME/etc/system/local
[default]
MAX_DAYS_HENCE = 40

after that I add file through step#5

but results are not as expected.

the events time is the time when I am uploading the events.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Did you executed step 4??

Just for troubleshooting, is it possible to keep local copy in the HF and execute step 5 again. And just check data on HF only.

I found steps For distributed environment please check below link.

https://blog.zivaro.com/splunk-product-timestamp-issue-solution

0 Karma

riqbal47010
Path Finder

hi kamlesh,

thanks fory your kind support.

I check the video link and found that to see the future date I have to select all times

thanks for your support

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...