I encountered some event timestamp issue at the Data preview for Windows2007 SP2 stated below. When i using the input file and configure at some other server, the timestamp and event date is the correct. what went wrong and how to resolve it?
9/25/01 4:31:20:000 AM 9/29/2014 12:42:00 AM ...........
9/25/01 4:33:50:000 AM 9/29/2014 12:43:33 AM .............
I think splunk doesn't pick the correct timestamp if as you say.Is it because the raw log has the same like string somewhere?
You can try to use the TIME_FORMAT property in $SPLUNK_HOME/etc/system/local/props.conf.
good luck 🙂