Hi All I am trying to index some log files that have been converted to tab delimited text files. These are being picked up by a Universal Forwarder and forwarded to a one-box Splunk Enterprise server. Splunk is ingesting them ok but it is indexing the UK dates dd/mm/yyyy as US format mm/dd/yyyy for all dates up to the 10th of each month. So, for October 8th (08/10/2020) for example I have no events indexed. The events collected on the 8th October have been indexed as August 10th. So far I have changed props.conf on both UF and Splunk Enterprise to look like this [SourceType] NO_BINARY_CHECK = 1 TIME_PREFIX = ^ TIME_FORMAT = %d/%m/%Y %H:%M:%S I have also set the SourceType within Splunk to use Timezone = GMT Timestamp format = %d/%m/%Y %H:%M:%S Timestamp Prefix = ^ Any ideas where I am going wrong?
... View more