Subscribe Our Newsletter

7 date formats impacted in Splunk starting 2020

By Bitsioinc 28/11/2019 6:14 pm
No Comments
date time xml splunk

You all must have heard of Splunk datetime recognition issues starting Jan 1st 2020. Below is visual representations of the date formats using regex that are impacted. You will have to change datetime.xml file in /opt/splunk/etc directory. You can see how the change impacts, please check Before & After the change.


Date format 1: CCYY

Date format 2: YY


splunk datetime xml format

Date format 3: CCYYMMDD

Date format 4: YYMMDD

Date format 5: MMDDCCYY

Date format 6: MMDDYY

Date format 7: UTC epoch time

date time xml splunk

Here is how to fix this, it’s very well documented at Splunk.

Leave Us A Reply

Your email address will not be published.