Getting Data In

After identifying future timestamps in indexed events, is there any way to adjust time / date after fixing the issue?

dschmidt_cfi
Path Finder

Basically, my wineventlog is showing a 'latest event' of Dec 01, 2020 and I need to revert that back to the proper time/date. I believe, from the props file, it read in the hour as the year. That is not the issue, but rather one of 'Is it possible to un-index events?' Think I already know the answer, but thought I would ask.

0 Karma

grijhwani
Motivator

There are methods for removing indexed data from visibility, and then re-indexing. But that would eat into your daily consumption cap. There is no method that I know of for bulk manipulation of extant index data.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...