Getting Data In

index future date events as today's date in _time

ayush1906
Path Finder

I am getting a future timestamped event, but I want to index it as default time of index. i.e. at the time when it got indexed.

Presently I have changed

MAX_DAYS_HENCE = 0

in my props.conf. But I found out that the event having tomorrow's date are getting index with tomorrow's date instead of today's date.

alt text

Like today its 23 July, I am looking for any events after today to be indexed for time 23 July. But in my case 24 July is taken as a valid date which should not be the case.

Any other workaround would be appreciated.

The source data is JSON response of API which I am indexing via python script and taking PED field as _time

0 Karma
1 Solution

adonio
Ultra Champion
0 Karma

adonio
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...