<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timestamp strftime issues in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572974#M10527</link>
    <description>&lt;P&gt;Yeah I don't know what I'm doing, but thanks for pointing that out.&amp;nbsp; I appreciate the untactful assist.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Oct 2021 14:33:33 GMT</pubDate>
    <dc:creator>walsborn</dc:creator>
    <dc:date>2021-10-29T14:33:33Z</dc:date>
    <item>
      <title>timestamp strftime issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572892#M10522</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I keep getting "&lt;SPAN class=""&gt;DateParserVerbose&lt;/SPAN&gt; [&lt;SPAN class=""&gt;6827&lt;/SPAN&gt; &lt;SPAN class=""&gt;merging&lt;/SPAN&gt;] &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;parse&lt;/SPAN&gt; &lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;first&lt;/SPAN&gt; &lt;SPAN class=""&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/SPAN&gt; (&lt;SPAN class=""&gt;75&lt;/SPAN&gt;) &lt;SPAN class=""&gt;characters&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;event.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Defaulting&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;previous&lt;/SPAN&gt; &lt;SPAN class=""&gt;event&lt;/SPAN&gt;" warnings.&lt;/P&gt;&lt;P&gt;The time stamp in the logs looks like: &lt;SPAN class=""&gt;2021/10/28T16:06:08.183-07:00&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;props.conf looks like:&lt;/P&gt;&lt;P&gt;DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = true&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 75&lt;BR /&gt;MAX_DAYS_AGO = 36500&lt;BR /&gt;MAX_DAYS_HENCE = 36500&lt;BR /&gt;TIME_FORMAT = %d-%b-%y %I.%M.%S.%6Q %p&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;TRUNCATE = 500000&lt;/P&gt;&lt;P&gt;Anyone know what my time_format should be instead?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 23:16:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572892#M10522</guid>
      <dc:creator>walsborn</dc:creator>
      <dc:date>2021-10-28T23:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp strftime issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572904#M10524</link>
      <description>&lt;P&gt;That TIME_FORMAT isn't even close so it' s no wonder Splunk is confused.&amp;nbsp; Try this one.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT = %Y/%m/%dT%H:%M:%S.%3N%:z&lt;/LI-CODE&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchReference/Commontimeformatvariables" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchReference/Commontimeformatvariables &lt;/A&gt;for the metacharacters used in TIME_FORMAT.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 00:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572904#M10524</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-29T00:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp strftime issues</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572974#M10527</link>
      <description>&lt;P&gt;Yeah I don't know what I'm doing, but thanks for pointing that out.&amp;nbsp; I appreciate the untactful assist.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 14:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/timestamp-strftime-issues/m-p/572974#M10527</guid>
      <dc:creator>walsborn</dc:creator>
      <dc:date>2021-10-29T14:33:33Z</dc:date>
    </item>
  </channel>
</rss>

