When adding data, You may set at
"Set Source Type", section "Advanced"
Name = MAX_DAYS_AGO
Value = -1
If you know about
https://en.wikipedia.org/wiki/Unix_time
you might expect that
1970-01-01
is the earliest date we can have in Splunk.
At least on Windows, indeed, the earliest date for Splunk is
1971-01-01
and not 1970-01-01 and even not 1970-12-31
PS: ISO date format is easily recognized by the pattern
Section "Timestamp"
Field: Timestamp format
Value: %Y-%m-%d
Sincerely
Rolf
... View more