Getting Data In
Highlighted

Best timestamp format

Builder

Hello guys,
could you confirm Splunk handles best US format (MM/DD/YYYY or YYYY/MM/DD for instance) where month preceding day?

Thanks.

0 Karma
Highlighted

Re: Best timestamp format

SplunkTrust
SplunkTrust

Splunk handles US date formats best, particularly mm/dd/yyyy over dd/mm/yyyy. That said, the date format doesn't matter if you specify TIME_FORMAT in your props.conf file (which you should do always).

---
If this reply helps you, an upvote would be appreciated.

View solution in original post