Getting Data In

splunk datetime after January 2020

snicol2017
New Member

Hi,

I want to know, I do not actually update my datetime.xml and I want to know if I update now for the data.
Do I need to re-ingest, reindex or restore all my server to 31 december 2019 and reingest the data if I haved.

I still version 7.1.9, if I update to 7.3.4 do I still have problem with my data.

Thx

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You should examine your data for mis-dated events. Also, check splunkd.log for errors in processing timestamps. If your data does not contain two-digit years then you should see no problems and nothing will need to be re-ingested.

Updating Splunk will not affect your existing data. It will ensure you are able to ingest data with two-digit years in the timestamp.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You should examine your data for mis-dated events. Also, check splunkd.log for errors in processing timestamps. If your data does not contain two-digit years then you should see no problems and nothing will need to be re-ingested.

Updating Splunk will not affect your existing data. It will ensure you are able to ingest data with two-digit years in the timestamp.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...