Getting Data In

How to add a custom year for a certain file

mikemichaleson
Engager

I am using Spunk Enterprise to upload log files and generate a timeline. I am uploading a linux secure.log file. It has a date and time stamp, but is missing the year. Splunk is automatically assigning the year 2018. I want to manually set the year to 2017 for just this one log file - not other files. Is there a way to automatically assign the year 2017, but keep the rest of date on the "Set Sourcetype" screen? Apparently you can edit props.conf, but I don't know if that will affect other files too.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...