Hi Splunker's,
Events coming for future dates, how to identify the future events and index them.
Thanks,
Hi,
Add the following configuration in props.conf along with time stamp recognition.
Props.conf:
MAX_DAYS_HENCE = <integer>
Sample configuration will look next 3 days,
MAX_DAYS_HENCE = 3
Maximum Integer value is 10950 (days).
Gothrough the following Links ,
http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Configuretimestamprecognition
http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/Propsconf
The answer by @vasanthmss is a good one and the one I would have given (but he got there first). The answer assumes that it is correct and proper for you go get events "from the future" and so we are accommodating/allowing them. But perhaps that is not what you desire; are you trying to fix/prevent events from the future?
we are looking for the hence day.
Thanks Woodcook,
Hi,
Add the following configuration in props.conf along with time stamp recognition.
Props.conf:
MAX_DAYS_HENCE = <integer>
Sample configuration will look next 3 days,
MAX_DAYS_HENCE = 3
Maximum Integer value is 10950 (days).
Gothrough the following Links ,
http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Configuretimestamprecognition
http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/Propsconf