Question on splunk to ignore the current day,
By using MAX_DAYS_AGO
or MAX_DAYS_HENCE
in props.conf?, if I set MAX_DAYS_AGO=0
for example will that ignore the current day?
Or maybe MAX_DIFF_SECS_AGO
or MAX_DIFF_SECS_HENCE
Splunk has to attach a timestamp to each event that it indexes. Normally, Splunk uses a timestamp that it finds in the text of the event. However, if Splunk can't find a timestamp, it will use the current data and time.
So, if you don't want Splunk to use the current date and time, you must tell Splunk where to find the proper date and time. It would help if you posted a few sample events (anonymized) for the community, so that we could help you figure out the proper settings.
I don't think that any of the settings that you mentioned will be helpful to you.