This props.conf is in my indexer, exactly, it belongs to the application I'm showing on splunk web interface, it works normally, just not between the 1st and the dd==mm.. Sure here a sample of my data.: splunkuser@linuxSearchHead.org:: /here/the/path/to/the/file/license_usage.txt
02/12/2021 09:10:00,Application Test V1,X00X000XX00,XXXXX00,CurrentUser,XXX,0,2022-01-01 00:59:00,XXX,0,2022-03-01 00:59:00,0000000000000000,0,0
02/12/2021 09:10:00,Application Test V1,X00X000XX00,XXXXX00,CurrentUser,XXX,0,2022-01-01 00:59:00,XXX,0,2022-03-01 00:59:00,0000000000000000,0,0
02/12/2021 09:10:00,Application Test V1,X00X000XX00,XXXXX00,CurrentUser,XXX,0,2022-01-01 00:59:00,XXX,0,2022-03-01 00:59:00,0000000000000000,0,0
... View more