|
After upgrading from 4.3 to 4.3.1, I have a few log files that splunk has changed the date format from month/day/year to year/month/day. The log files that have changed are being forwarded from splunk 4.3 full (not the universal forwarder) to my splunk index server which is the one I upgraded to 4.3.1. In an effort to resolve the issue I upgraded the forwarder to 4.3.1, but this did not fix the issue. The log files have always been Y/M/D format and up until the upgrade Splunk had parsed these as M/D/Y without any changed using the syslog template. |