Hi guys!
I load a log file of apache to the splunk.
In the "Set Source Type" window the system missed the day in the timestamp and I unsuccess to modify it manually.
Someone know this problem?
Hello @AmyDeluxe0506,
I think the problem is related to the fact that you're parsing a very old log file (from 2004).
I would suggest you to use the Advanced Timestamp option (leave that part empty)
And to add, inside the "Advanced" window this field :
MAX_DAYS_AGO --> 8035 (or even a greater integer)
Let me know if that solved your issue!
Regards,
GaetanVP
Try %d/%b/%Y:%H:%M:%S %z as the timestamp format.