Splunk Search

"DB CONNECT" app timestamp is not working

changwoo
Communicator

i am using the db connect app to get the data from my db.
i have a date formate like 2005-05-30

and my input.conf is alt text

and the error log is like this alt text

plz help~

1 Solution

mchang_splunk
Splunk Employee
Splunk Employee

Please try to increase MAX_DAYS_AGO in props.conf.
Here is the answer you can refer to:
http://answers.splunk.com/answers/24668/how-do-you-limit-the-amount-of-time-that-splunk-looks-into-t...

View solution in original post

mchang_splunk
Splunk Employee
Splunk Employee

Please try to increase MAX_DAYS_AGO in props.conf.
Here is the answer you can refer to:
http://answers.splunk.com/answers/24668/how-do-you-limit-the-amount-of-time-that-splunk-looks-into-t...

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...