Getting Data In

Splunk indexing data incorrect


I'm having trouble indexing my logs.
After investigations, I noticed that the splunk started indexing the data with the wrong date. Our log has the format dd /mm/yy, while splunk since last week began interpreting the dates as mm yy/dd, playing data from 04/18/19 to 04/19/18 - April 19, 2018 .
How can I fix this?

0 Karma


You need to specify the TIME_FORMAT attribute for that sourcetype in props.conf. In fact, it's a Best Practice to specify TIME_FORMAT for all sourcetypes to prevent this type of problem.
The data already indexed cannot be changed.

If this reply helps you, an upvote would be appreciated.
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!