All Apps and Add-ons

How to get the latest logs from a source which does not have timestamp

vrmandadi
Builder

I have configured an input through REST API to get data into splunk .Recently I have disabled one input since there was high volume of data coming in.If we enable it back do we get all the historical data , since there is no time stamp? . How to get only the latest data from the time it was enabled and ignore the historical data

Sample event:

[quartzJobExecutor-1] INFO c.c.c.r.c.s.m.i.DataSetMatcherServiceImpl - Computing similarity scores took 0 ms

0 Karma

woodcock
Esteemed Legend

It depends on the design of the input. The developer should have documented how it works.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It depends on the API being used. Some will return all events if no start time is specified, but have a limit to how far back they will go.

Why do you not have a timestamp? You could set DATETIME_CONFIG = current for the sourcetype to ensure all events get a timestamp.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vrmandadi
Builder

The source by default dont have timestamp. If we set DATETIME_CONFIG = current , does it ignore historical data and gets only the data at the time of configuration

0 Karma

richgalloway
SplunkTrust
SplunkTrust

DATETIME_CONFIG = current assigns a timestamp to events as they are indexed. It doesn't affect data already indexed. Having a timestamp on your data means you can pick up where you left off.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...