Timestamp with no year | Splunk Timestamp Extraction Masterclass 101 | Soft Mania

Опубликовано: 26 Март 2026
на канале: Soft Mania
101
5

Timestamps with no year?

Last but not least, how Splunk handles the Timestamps with no year.
Let’s take an example of data, here we have Day 17, Month 03, and time as well. But the year is not available.
If we index this data to Splunk, what will happen?
The splunk document says that Splunk will take the year value from the current system clock time or last parsed event date.
So we indexed this data and took some observations. No year is in the events but Splunk has taken the year value as 2023 from the current clock time.
But how? Is there a Logic or Magic? Of course, Splunk has its own logic.
We will discuss those logics moving forward.
Let’s understand the First Logic,
In this data, we have a date & month 17-Mar, so Splunk keeps them as it is.
Then it takes today's date & month 11-Sept….. (This video was recorded on 11-Sept so please don’t confuse this).
Splunk compares today’s date with the event date, and finds the event date is lesser than today’s date.
So Splunk will consider the current year and assign it to the timestamp.
In short, “If the event date & month is less than today’s date & month, Splunk takes the current year”.
Here we have another example,
In this data, we have a date & month 17-Dec, so Splunk keeps them as it is.
Then it takes today's date & month 11-Sept… (This video was recorded on 11-Sept so please don’t confuse this).
Splunk compares today’s date with the event date and finds the event date is greater than today’s date.
So Splunk will take the previous year (which is 2022) and assign it to the timestamp.
In short, “If the event date & month is greater than today’s date and month, Splunk takes the previous year.”
In the case of the special dates with no year, like this data from the 29th of February (which is a Leap Year date),
Splunk keeps the date as it is, takes the current year, and checks if it is a Leap Year.
If it is a Leap year, then it will keep the same year. But 2023 is not a Leap Year. Sp Splunk takes the recent Leap Year and assigns it to the timestamp.
In short, “If the current year is a Leap year, then it will be taken. If not, Last leap year will be considered”


🆓🆓Free Masterclasses: (With live session 👨‍💻 at the end)🆓🆓

Splunk Timestamp Extraction Masterclass 101:
https://splunk.softmania.in/course/sp...

Scenario-based Splunk Admin Use Cases - Part 1:
https://splunk.softmania.in/course/sc...

Splunk Search Commands Masterclass 101:
https://splunk.softmania.in/course/sp...

👑👑Soft Mania Premium Subscription👑👑
One-time Subscription with Lifetime access to all masterclasses.
For more details, visit: https://splunk.softmania.in/course/so...

(Subscription charges will spike by 40% on 01-Mar-2024. 📈)

#splunk #splunkadmin #splunkblogs #splunkengineer #splunklife #softmania #splunkmania"