I'm having trouble indexing my logs.
After investigations, I noticed that the splunk started indexing the data with the wrong date. Our log has the format dd /mm/yy, while splunk since last week began interpreting the dates as mm yy/dd, playing data from 04/18/19 to 04/19/18 - April 19, 2018 .
How can I fix this?
You need to specify the TIME_FORMAT
attribute for that sourcetype in props.conf. In fact, it's a Best Practice to specify TIME_FORMAT
for all sourcetypes to prevent this type of problem.
The data already indexed cannot be changed.