Getting Data In

After identifying future timestamps in indexed events, is there any way to adjust time / date after fixing the issue?

dschmidt_cfi
Path Finder

Basically, my wineventlog is showing a 'latest event' of Dec 01, 2020 and I need to revert that back to the proper time/date. I believe, from the props file, it read in the hour as the year. That is not the issue, but rather one of 'Is it possible to un-index events?' Think I already know the answer, but thought I would ask.

0 Karma

grijhwani
Motivator

There are methods for removing indexed data from visibility, and then re-indexing. But that would eat into your daily consumption cap. There is no method that I know of for bulk manipulation of extant index data.

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...