No matter what format I attempt to force upon historical timestamps:
either
Feb 11, 2004 01:23:45
or
2004-02-11 01:23:45
splunk ignores years that fall before 2006 while the rest of the timestamp is preserved. The current year (2011) is substituted for years <= 2006.
Is this a configurable parameter/range I'm missing?
Yes, your dates are being restricted by the default MAX_DAYS_AGO
setting in props.conf. The default is 2000 (days), which currently puts the limit at September of 2005.
Yes, your dates are being restricted by the default MAX_DAYS_AGO
setting in props.conf. The default is 2000 (days), which currently puts the limit at September of 2005.