When adding data, You may set at
"Set Source Type", section "Advanced"
Name = MAX_DAYS_AGO
Value = -1
If you know about
you might expect that
is the earliest date we can have in Splunk.
At least on Windows, indeed, the earliest date for Splunk is
and not 1970-01-01 and even not 1970-12-31
PS: ISO date format is easily recognized by the pattern
Field: Timestamp format
... View more