<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606727#M13436</link>
    <description>&lt;P&gt;Thank you for the response, but it does not provide the information I need to answer the question.&lt;/P&gt;&lt;P&gt;What settings are in props.conf for the sourcetype other than the 3 mentioned?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the sourcetype name in props.conf match the sourcetype name in inputs.conf?&lt;/P&gt;&lt;P&gt;Do other props.conf files have the same sourcetype in them?&amp;nbsp; Use the &lt;FONT face="courier new,courier"&gt;splunk btool&lt;/FONT&gt; command to see the exact settings Splunk is using for the sourcetype.&lt;/P&gt;&lt;P&gt;Is the props.conf file installed on all indexers and heavy forwarders?&amp;nbsp; Were those indexers and HFs restarted after receiving the props.conf file?&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jul 2022 12:34:34 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-07-23T12:34:34Z</dc:date>
    <item>
      <title>Why did Splunk fail to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606694#M13432</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have onboarded the data into Splunk which we have multiple timestamps in the event in different formats. I believe my props settings are correct however it's giving an error in Splunkd.log. Please Advise&lt;/P&gt;
&lt;P&gt;Error Details :&lt;/P&gt;
&lt;P&gt;DateParserVerbose [99999 merging_0] - Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (16) characters of event. Defaulting to timestamp of previous event&lt;/P&gt;
&lt;P&gt;Event Details:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jul 10 14:19:08 abcdefgh81 dnsmask Jul 10 14:19:08 dnsmask[1520]: cached abcdefg43.wellness.com is 10.220.200.72&lt;/P&gt;
&lt;P&gt;Jul 10 14:19:08 abcdefgh81 dnsmask -- [10/July/2022:18:10:10 -9900] dnsmask[1520]: cached abcdefg43.wellness.com is 10.220.200.72&lt;/P&gt;
&lt;P&gt;Here are my props settings&lt;/P&gt;
&lt;P&gt;TIME_PREFIX=^&lt;/P&gt;
&lt;P&gt;TIME_FORMAT=%b %d %H:%M:%S&lt;/P&gt;
&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD = 16&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 21:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606694#M13432</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2022-07-25T21:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606696#M13433</link>
      <description>&lt;P&gt;Are those *all* of the props for that sourcetype?&amp;nbsp; Are they in the *right* sourcetype for that data?&amp;nbsp; Have you used btool (&lt;FONT face="courier new,courier"&gt;splunk btool --debug props list &lt;EM&gt;&amp;lt;&amp;lt;sourcetype&amp;gt;&amp;gt;&lt;/EM&gt;&lt;/FONT&gt;) to ensure the settings aren't being overridden by another app?&lt;/P&gt;&lt;P&gt;On which instance are the props defined?&amp;nbsp; They should be on all indexers and heavy forwarders (if any).&amp;nbsp; Did you restart the instances after loading the props?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 21:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606696#M13433</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-22T21:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606699#M13434</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Yes , The sourcetype is created exclusively for this data/app. The interesting part is yes we have multiple time formats in same source coming from lot of servers.&lt;/P&gt;&lt;P&gt;My understanding is If we have multiple time formats in the event it should look at beginning of the event as I mentioned in TIME_PREFIX&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 21:16:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606699#M13434</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2022-07-22T21:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606727#M13436</link>
      <description>&lt;P&gt;Thank you for the response, but it does not provide the information I need to answer the question.&lt;/P&gt;&lt;P&gt;What settings are in props.conf for the sourcetype other than the 3 mentioned?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the sourcetype name in props.conf match the sourcetype name in inputs.conf?&lt;/P&gt;&lt;P&gt;Do other props.conf files have the same sourcetype in them?&amp;nbsp; Use the &lt;FONT face="courier new,courier"&gt;splunk btool&lt;/FONT&gt; command to see the exact settings Splunk is using for the sourcetype.&lt;/P&gt;&lt;P&gt;Is the props.conf file installed on all indexers and heavy forwarders?&amp;nbsp; Were those indexers and HFs restarted after receiving the props.conf file?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 12:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606727#M13436</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-23T12:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606935#M13443</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Thank you for your response .Other settings are&lt;/P&gt;&lt;P&gt;CHARSET = UTF-8&lt;/P&gt;&lt;P&gt;LINE_BREAKER =&amp;nbsp;([\r\n]+)&lt;/P&gt;&lt;P&gt;NO_BINARY_CHECK = True&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = False&lt;/P&gt;&lt;P&gt;TZ = UTC&lt;/P&gt;&lt;P&gt;-- Yes props.conf sourcetype match with inputs.conf sourcetype&lt;/P&gt;&lt;P&gt;There is only 1 sourcetype created for this . This is Splunk Cloud Env&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 19:40:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606935#M13443</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2022-07-25T19:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to parse the timestamp in first MAX_TIMESTAMP_LOOKAHEAD?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606943#M13444</link>
      <description>&lt;P&gt;Thanks for the info.&amp;nbsp; Those props look fine.&amp;nbsp; Are they installed on indexers as well as HFs?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 19:51:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-did-Splunk-fail-to-parse-the-timestamp-in-first-MAX/m-p/606943#M13444</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-25T19:51:58Z</dc:date>
    </item>
  </channel>
</rss>

