I have a field in .csv file that have future dates. while uploading to Splunk, it shows the below error message and don't show any record after uploading.
Future dates are must to show. The field containing future dates is 'Start_Time' which is also _time. I am using that _time in my query also.
Any suggestion will be helpful!
The solution as the tooltip suggests is to increase the MAXDAYSHENCE setting in your props.conf file.
Note, this can be source, sourcetype, or host specific.
I increased MAXDAYSHENCE to 20 days in props.config. But the result is still same, it is not reflecting, I closed Splunk and open it again. My data is one week ahead of current date.