Getting Data In

timestamp is outside of acceptable window

rvisj
New Member

I have a field in .csv file that have future dates. while uploading to Splunk, it shows the below error message and don't show any record after uploading.
Future dates are must to show. The field containing future dates is 'Start_Time' which is also _time. I am using that _time in my query also.

.alt text

Any suggestion will be helpful!

0 Karma

rjthibod
Champion

The solution as the tooltip suggests is to increase the MAX_DAYS_HENCE setting in your props.conf file.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf#Timestamp_extraction_configurati...

Note, this can be source, sourcetype, or host specific.

rvisj
New Member

I increased MAX_DAYS_HENCE to 20 days in props.config. But the result is still same, it is not reflecting, I closed Splunk and open it again. My data is one week ahead of current date.

0 Karma

rjthibod
Champion

Sorry for the delay. Was out on vacation.

Did you restart Splunk or just close the browser?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...