Getting Data In

Best timestamp format

splunkreal
Motivator

Hello guys,
could you confirm Splunk handles best US format (MM/DD/YYYY or YYYY/MM/DD for instance) where month preceding day?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk handles US date formats best, particularly mm/dd/yyyy over dd/mm/yyyy. That said, the date format doesn't matter if you specify TIME_FORMAT in your props.conf file (which you should do always).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Splunk handles US date formats best, particularly mm/dd/yyyy over dd/mm/yyyy. That said, the date format doesn't matter if you specify TIME_FORMAT in your props.conf file (which you should do always).

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...