Am getting a warning of
DateParserVerbose - Accepted time (Wed Feb 14 17:01:12 2024) is suspiciously far away from previous event (Thu jan 18 17:01:12 2024) is still acceptable because it was extracted by the same pattern
Is there any configuration that can help take this error away in splunk
Make sure the props.conf settings for that sourcetype have the correct time settings. Specifically, check the TIME_PREFIX, TIME_FORMAT, and MAX_TIMESTAMP_LOOKAHEAD values.
Confirm the data source is sending the right events.
The first event that came in doesnt have a timestamp which is the reason for the error but the other events are extracted properly