Getting Data In

Best timestamp format

splunkreal
Motivator

Hello guys,
could you confirm Splunk handles best US format (MM/DD/YYYY or YYYY/MM/DD for instance) where month preceding day?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk handles US date formats best, particularly mm/dd/yyyy over dd/mm/yyyy. That said, the date format doesn't matter if you specify TIME_FORMAT in your props.conf file (which you should do always).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Splunk handles US date formats best, particularly mm/dd/yyyy over dd/mm/yyyy. That said, the date format doesn't matter if you specify TIME_FORMAT in your props.conf file (which you should do always).

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...