<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need assistance in writing props- failed to parse timestamp? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617695#M14264</link>
    <description>&lt;P&gt;The message "failed to parse timestamp" means Splunk could not find a timestamp in your logs that matches what it expected.&amp;nbsp; Perhaps, and this appears to the case here, there is no timestamp at all.&lt;/P&gt;&lt;P&gt;To fix the problem, make sure the props.conf settings correctly tell Splunk where to find the timestamp in each event and how it is formatted.&amp;nbsp; Specifically, include these settings:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX
TIME_FORMAT
MAX_TIMESTAMP_LOOKAHEAD&lt;/LI-CODE&gt;&lt;P&gt;For logs that have no timestamp at all, then let Splunk know that with this props.conf setting, which uses the current time as the event time.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DATETIME_CONFIG = CURRENT&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 13:10:35 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-10-19T13:10:35Z</dc:date>
    <item>
      <title>Need assistance in writing props: Why is search failing to parse timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617633#M14257</link>
      <description>&lt;P&gt;1. I have below logs:&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call)&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call)&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call), unable to find the logs from this server.&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call)&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call)&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call), unable to find the logs from this server.&lt;BR /&gt;server6z: INFO could not find the logs under this path(apimanager call)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;i have mentioned in my props&lt;BR /&gt;should_linemerge=false&lt;BR /&gt;line_breaker=([\r\n]+)&lt;BR /&gt;&lt;BR /&gt;but i am seeing error like failed to parse timestamp&lt;BR /&gt;defaulting to file modtime.&lt;BR /&gt;How to resolve this issue.&lt;BR /&gt;&lt;BR /&gt;2. I am getting the same issue as above for this type of logs as well&lt;BR /&gt;&lt;BR /&gt;Sample logs:&lt;BR /&gt;/path/svgt/app/loadscript/file.com: coloumn12: /path/svgt/app/loadscript/file.com: not able to view file&lt;BR /&gt;/applicatins/dir/wrd-start/loadscript/filedata.com: line24:&amp;nbsp;/applicatins/dir/wrd start/loadscript/filedata.com: not able to read the files&lt;BR /&gt;/path/svgt/app/loadscript/file.com: coloumn12: /path/svgt/app/loadscript/file.com: not able to view file&lt;BR /&gt;/applicatins/dir/wrd-start/loadscript/filedata.com: line24:&amp;nbsp;/applicatins/dir/wrd start/loadscript/filedata.com: not able to read the files&lt;BR /&gt;/path/svgt/app/loadscript/file.com: coloumn12: /path/svgt/app/loadscript/file.com: not able to view file&lt;BR /&gt;/path/svgt/app/loadscript/file.com: coloumn12: /path/svgt/app/loadscript/file.com: not able to view file&lt;BR /&gt;/applicatins/dir/wrd-start/loadscript/filedata.com: line24:&amp;nbsp;/applicatins/dir/wrd start/loadscript/filedata.com: not able to read the files&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 15:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617633#M14257</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2022-10-19T15:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance in writing props- failed to parse timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617695#M14264</link>
      <description>&lt;P&gt;The message "failed to parse timestamp" means Splunk could not find a timestamp in your logs that matches what it expected.&amp;nbsp; Perhaps, and this appears to the case here, there is no timestamp at all.&lt;/P&gt;&lt;P&gt;To fix the problem, make sure the props.conf settings correctly tell Splunk where to find the timestamp in each event and how it is formatted.&amp;nbsp; Specifically, include these settings:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX
TIME_FORMAT
MAX_TIMESTAMP_LOOKAHEAD&lt;/LI-CODE&gt;&lt;P&gt;For logs that have no timestamp at all, then let Splunk know that with this props.conf setting, which uses the current time as the event time.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DATETIME_CONFIG = CURRENT&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617695#M14264</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-19T13:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need assistance in writing props- failed to parse timestamp?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617773#M14269</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;DATETIME_CONFIG = CURRENT&lt;/PRE&gt;&lt;P&gt;worked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 01:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Need-assistance-in-writing-props-Why-is-search-failing-to-parse/m-p/617773#M14269</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2022-10-20T01:12:06Z</dc:date>
    </item>
  </channel>
</rss>

