Splunk Enterprise

Anyway to turn off Splunk automatic detection of timestamp fields for csv indexing?

briancronrath
Contributor

I have a csv I ingest where I just want it to default to the date of last modified for the csv... there are no actual timestamp columns in this csv, however splunk keeps automatically trying to treat some of the longer integer values as epochs, causing several rows to just get thrown out because they are detected as being decades in the past. Is there anyway I can turn this feature off per sourcetype?

Tags (1)
0 Karma

DalJeanis
Legend

briancronrath
Contributor

it's strange.. I've tried setting DATETIME_CONFIG = NONE, MAX_DAYS_AGO=0, MAX_TIMESTAMP_LOOKAHEAD=1, it doesn't seem like any of these have any effect, I keep getting this message:

06-07-2018 10:28:06.446 -0700 WARN DateParserVerbose - A possible timestamp match (Sun Jun 20 04:40:06 2010) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: [...]

0 Karma

pradeepkumarg
Influencer

Try setting MAX_TIMESTAMP_LOOKAHEAD to a lower value in the props.conf for the sourcetype so that it doesn't reach to the point where you have the long integers? There could be other elegant solutions.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...