Getting Data In

What can cause an issue of a different time extraction over the same source type / log type?

Path Finder


We've got a source type that extracts the date correctly (01/12/2018 in log, 01/12/2018 in Splunk). We've got a new host going to a new index with the same source type, but now the date is incorrect (01/12/2018 in log, 12/01/2018 in Splunk).

What can cause this issue of a different time extraction over the same sourcetype / log type?

0 Karma

Ultra Champion

For this specific sourcetype, did you specify explicitly the date/time extraction in props.conf?

0 Karma


Which operating system is running on the new host?

My first thought is that the system language is different on the new host. Depending on the language, the date might get displayed/interpreted differently.

To demonstrate on CentOS:

# localectl
System Locale: LANG=en_US.UTF-8
# date +"%x"

# localectl | grep Locale
System Locale: LANG=de_DE.utf8
# date +"%x"
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!