Splunk Enterprise

Anyway to turn off Splunk automatic detection of timestamp fields for csv indexing?

briancronrath
Contributor

I have a csv I ingest where I just want it to default to the date of last modified for the csv... there are no actual timestamp columns in this csv, however splunk keeps automatically trying to treat some of the longer integer values as epochs, causing several rows to just get thrown out because they are detected as being decades in the past. Is there anyway I can turn this feature off per sourcetype?

Tags (1)
0 Karma

DalJeanis
Legend

briancronrath
Contributor

it's strange.. I've tried setting DATETIME_CONFIG = NONE, MAX_DAYS_AGO=0, MAX_TIMESTAMP_LOOKAHEAD=1, it doesn't seem like any of these have any effect, I keep getting this message:

06-07-2018 10:28:06.446 -0700 WARN DateParserVerbose - A possible timestamp match (Sun Jun 20 04:40:06 2010) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: [...]

0 Karma

pradeepkumarg
Influencer

Try setting MAX_TIMESTAMP_LOOKAHEAD to a lower value in the props.conf for the sourcetype so that it doesn't reach to the point where you have the long integers? There could be other elegant solutions.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...