Setting dates in timestamps
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Setting dates in timestamps
Whenever the Splunk Server begins to index a new source, it sets timestamps in this order:
- It sets the current date as a fallback date.
- It then attempts to extract a date in the "source::" string. If it succeeds, it sets that date as the fallback date.
- When timestamping each event, if it has a date, that date is used and becomes the new fallback date.
- If an event's timestamp has a time but no date, the fallback date is used.
This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.