Getting Data In

How to add a custom year for a certain file

mikemichaleson
Engager

I am using Spunk Enterprise to upload log files and generate a timeline. I am uploading a linux secure.log file. It has a date and time stamp, but is missing the year. Splunk is automatically assigning the year 2018. I want to manually set the year to 2017 for just this one log file - not other files. Is there a way to automatically assign the year 2017, but keep the rest of date on the "Set Sourcetype" screen? Apparently you can edit props.conf, but I don't know if that will affect other files too.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...