<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extract time with sc4s in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760575#M24186</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;, I tried what you propose but unfortunately, it doesn't work :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anissabnk_0-1777536752909.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41995i13DAB5653DE076C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anissabnk_0-1777536752909.png" alt="anissabnk_0-1777536752909.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That's what I did, on my .conf files :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;&lt;STRONG&gt;props.conf :&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;# KSCONF-NO-SORT&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[st_postfix]&lt;/P&gt;&lt;P&gt;# Note: Extending Splunk default settings (See $SPLUNK_HOME/etc/system/default/props.conf&lt;BR /&gt;pulldown_type = 0&lt;/P&gt;&lt;P&gt;# Ignore le tag (EXTERNE/INTERNE/RIE/CLE) et pointe sur le timestamp&lt;BR /&gt;TIME_PREFIX = ^(?:EXTERNE|INTERNE|RIE|CLE)\s+&lt;/P&gt;&lt;P&gt;# Format du timestamp : "Apr 28 10:45:00"&lt;BR /&gt;TIME_FORMAT = %b %d %H:%M:%S&lt;/P&gt;&lt;P&gt;# Augmente la fenêtre de recherche pour inclure le timestamp + nom d'hôte&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 25&lt;/P&gt;&lt;P&gt;# Désactive la fusion de lignes&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;# Extract the subject if enabled in Postfix's configuration&lt;BR /&gt;REPORT-subject = postfix_subject&lt;BR /&gt;# Extract to/from/message-id/helo (without the '&amp;lt;&amp;gt;'s)&lt;BR /&gt;REPORT-angle_brackets = postfix_angle_brackets&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;EXTRACT-queue_id = postfix/[\w/]+\[\d+\]:\s+(?&amp;lt;queue_id&amp;gt;[A-Fa-f0-9]{6,20}):&lt;BR /&gt;EXTRACT-bounce = postfix/bounce\[\d+\]: [a-fA-F0-9]{6,20}: (?&amp;lt;bounce_reason&amp;gt;[^:]+): (?&amp;lt;bounce_queue_id&amp;gt;[a-fA-F0-9]{6,20})$&lt;BR /&gt;EXTRACT-status_reject = postfix/smtpd\[\d+\]: (?:NOQUEUE|[A-Fa-f0-9]{6,20}): (?&amp;lt;status&amp;gt;reject):&lt;BR /&gt;EXTRACT-reason = status=[^\s]+\s+\((?&amp;lt;reason&amp;gt;.*)\)$&lt;BR /&gt;EXTRACT-reject_reason = : (?&amp;lt;reject_reason&amp;gt;[^;:]+);&lt;BR /&gt;EXTRACT-dest = relay=(?&amp;lt;dest_host&amp;gt;[^\[ ,]+)\[(?&amp;lt;dest_ip&amp;gt;[^: \]]+)\](?::(?&amp;lt;dest_port&amp;gt;\d+))?&lt;BR /&gt;EXTRACT-remote_queue = queued as (?&amp;lt;xref&amp;gt;[A-Fa-f0-9]+) in reason&lt;BR /&gt;EXTRACT-status_code = status=\w+ \((?:host \S+ said:\s*)?(?&amp;lt;status_code_short&amp;gt;\d+)&lt;BR /&gt;EXTRACT-src-connect = (?:dis)?connect(?:ion after (?:HELO|CONNECT))? from (?:(?&amp;lt;src_host&amp;gt;[^\[]+)\[(?&amp;lt;src_ip&amp;gt;[\d.]+)|(?&amp;lt;src&amp;gt;.*))&lt;BR /&gt;# Extration of the different delays (cf. &lt;A href="http://logreporters.sourceforge.net/faq.html#percentiles" target="_blank"&gt;http://logreporters.sourceforge.net/faq.html#percentiles&lt;/A&gt;)&lt;BR /&gt;EXTRACT-delays = ^(?&amp;lt;time_before_queue&amp;gt;[^/]+)/(?&amp;lt;time_in_queue&amp;gt;[^/]+)/(?&amp;lt;time_connecting&amp;gt;[^/]+)/(?&amp;lt;time_transmitting&amp;gt;[^$]+)$ in delays&lt;/P&gt;&lt;P&gt;# Rename fields for CIM compliance with the Email data model&lt;BR /&gt;FIELDALIAS-status_code = dsn as status_code&lt;BR /&gt;#FIELDALIAS-status_code = status_code_short as status_code&lt;BR /&gt;FIELDALIAS-protocol = proto as protocol&lt;BR /&gt;FIELDALIAS-filter_action = reject_reason as filter_action&lt;BR /&gt;FIELDALIAS-internal_message_id = queue_id AS internal_message_id&lt;BR /&gt;FIELDALIAS-process_id = pid AS process_id&lt;BR /&gt;FIELDALIAS-src_user = from as src_user&lt;BR /&gt;FIELDALIAS-recipient = to as recipient&lt;BR /&gt;FIELDALIAS-orig_recipient = orig_to as orig_recipient&lt;BR /&gt;FIELDALIAS-recipient_count = nrcpt as recipient_count&lt;/P&gt;&lt;P&gt;# Don't extract 'src_host' if "unknown" (typical with reverse DNS disabled)&lt;BR /&gt;EVAL-src=coalesce(src, nullif(src_host, "unknown"), src_ip)&lt;BR /&gt;# FIELDALIAS-src=src_host AS src, src_ip AS src&lt;BR /&gt;EVAL-dest = coalesce(dest, nullif(dest_host, "unknown"), dest_ip)&lt;/P&gt;&lt;P&gt;LOOKUP-consts = postfix_consts sourcetype OUTPUT protocol, vendor, product&lt;BR /&gt;LOOKUP-actions = postfix_actions status OUTPUT action&lt;/P&gt;&lt;P&gt;# Email CIM requires the delay field to be in milliseconds&lt;BR /&gt;EVAL-delay = delay*1000&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# Suppression des tags injectés par rsyslog (EXTERNE, INTERNE, RIE, CLE)&lt;BR /&gt;SEDCMD-remove_tag = s/^(EXTERNE|INTERNE|RIE|CLE)\s+//&lt;/P&gt;&lt;P&gt;#Extraction du _time&lt;BR /&gt;TRANSFORMS-getCorrectSC4STime = getCorrectSC4STime&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;&lt;STRONG&gt;transforms.conf :&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;# KSCONF-NO-SORT&lt;/P&gt;&lt;P&gt;[postfix_angle_brackets]&lt;BR /&gt;# Strip out the '&amp;lt;' or '&amp;gt;' from the value of the postfix log messages.&lt;BR /&gt;# Examples:&lt;BR /&gt;# to=&amp;lt;jdoe@aol.com&amp;gt;&lt;BR /&gt;# from=&amp;lt;bob@example.com&amp;gt;&lt;BR /&gt;# message-id=&amp;lt;20360611180017.4944318FE39@webapp.example.com&amp;gt;&lt;BR /&gt;# helo=&amp;lt;localhost.localdomain&amp;gt;&lt;BR /&gt;REGEX = [ ](to|from|message-id|helo)=&amp;lt;([^&amp;lt;&amp;gt; ]+)&amp;gt;&lt;BR /&gt;FORMAT = $1::$2&lt;/P&gt;&lt;P&gt;[postfix_subject]&lt;BR /&gt;# Logging the subject header requires changes to postfix config (disabled by default)&lt;BR /&gt;# main.cf: header_checks = regexp:/etc/postfix/header_checks&lt;BR /&gt;# header_checks: /^subject:/ WARN&lt;BR /&gt;# Example event:&lt;BR /&gt;# Nov 4 10:57:01 localhost postfix/cleanup[22492]: 2290326720: warning: header subject: test email from localhost[127.0.0.1]; from= to= proto=SMTP helo=&lt;BR /&gt;REGEX = header [Ss]ubject: (?&amp;lt;subject&amp;gt;.+?) from [^;]+;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# Lookups&lt;/P&gt;&lt;P&gt;[postfix_consts]&lt;BR /&gt;# Constant fields applied uniformly to ALL events&lt;BR /&gt;# Note: More efficient than using an 'EVAL-*' for these fields.&lt;BR /&gt;filename = postfix_consts.csv&lt;/P&gt;&lt;P&gt;[postfix_actions]&lt;BR /&gt;# Convert Postfix's 'status' messages into CIM 'actions' (as best as possible)&lt;BR /&gt;filename = postfix_actions.csv&lt;/P&gt;&lt;P&gt;#Extraction du _time&lt;BR /&gt;[getCorrectSC4STime]&lt;BR /&gt;INGEST_EVAL = _time=strptime(_raw,"%B %d %H:%M:%S")&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2026 08:20:03 GMT</pubDate>
    <dc:creator>anissabnk</dc:creator>
    <dc:date>2026-04-30T08:20:03Z</dc:date>
    <item>
      <title>extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760565#M24184</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well. I’m having some issues with log parsing on the rsyslog side.&lt;BR /&gt;Let me explain: I’m working with three machines:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;- Linux sources (where I store the files to be read)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;- SC4S &lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;- Splunk machine&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;- TA-postfix&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;U&gt;SC4S :&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I'm working with this configuration file, which allows me to define the index and the source type&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;logos-postfix-parser.conf&lt;/FONT&gt; : &lt;/STRONG&gt;/opt/sc4s/local/config/app_parsers/syslog&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;# the block parser is where the "parsing" of the event happens and enrichment of meta data&lt;/P&gt;&lt;P&gt;# sample: &amp;lt;111&amp;gt; Mar 24 10:45:00 osnixexample: this is a test&lt;/P&gt;&lt;P&gt;block parser logos-postfix-rie-parser() {&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rewrite {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; r_set_splunk_dest_default(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; index("idx_messagerie_rie")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourcetype("st_postfix")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vendor("postfix")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; product("logos")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; );&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;block parser logos-postfix-interne-parser() {&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rewrite {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; r_set_splunk_dest_default(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; index("idx_messagerie_relaisinterne")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourcetype("st_postfix")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vendor("postfix")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; product("logos")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; );&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;block parser logos-postfix-externe-parser() {&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rewrite {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; r_set_splunk_dest_default(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; index("idx_messagerie_relaisexterne")&amp;nbsp; # Index cible&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourcetype("st_postfix")&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # Sourcetype personnalisé&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vendor("postfix")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; product("logos")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; );&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;block parser logos-postfix-externe-cle-parser() {&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rewrite {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; r_set_splunk_dest_default(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; index("idx_messagerie_relaisexterne_cle")&amp;nbsp; # Index cible&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sourcetype("st_postfix")&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # Sourcetype personnalisé&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vendor("postfix")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; product("logos")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; );&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;application logos-postfix-rie[sc4s-syslog] {&lt;/P&gt;&lt;P&gt;&amp;nbsp; filter {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; #program('f_rie' type(string) flags(prefix));&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; program('RIE' type(string) flags(prefix));&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;&amp;nbsp; parser {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; logos-postfix-rie-parser();&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;application logos-postfix-interne[sc4s-syslog] {&lt;/P&gt;&lt;P&gt;&amp;nbsp; filter {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; program('INTERNE' type(string) flags(prefix));&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; #program('f_interne' type(string) flags(prefix));&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;&amp;nbsp; parser {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; logos-postfix-interne-parser();&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;application logos-postfix-externe[sc4s-syslog] {&lt;/P&gt;&lt;P&gt;&amp;nbsp; filter {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; program('EXTERNE' type(string) flags(prefix));&amp;nbsp; # &amp;lt;-- Filtre sur le tag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; #program('f_externe' type(string) flags(prefix));&lt;/P&gt;&lt;P&gt;&amp;nbsp;};&lt;/P&gt;&lt;P&gt;&amp;nbsp; parser {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; logos-postfix-externe-parser();&amp;nbsp; # &amp;lt;-- Utilise le parser dédié&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;application logos-postfix-externe-cle[sc4s-syslog] {&lt;/P&gt;&lt;P&gt;&amp;nbsp; filter {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; program('CLE' type(string) flags(prefix));&amp;nbsp; # &amp;lt;-- Filtre sur le tag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; #program('f_externe' type(string) flags(prefix));&lt;/P&gt;&lt;P&gt;&amp;nbsp;};&lt;/P&gt;&lt;P&gt;&amp;nbsp; parser {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; logos-postfix-externe-cle-parser();&amp;nbsp; # &amp;lt;-- Utilise le parser dédié&lt;/P&gt;&lt;P&gt;&amp;nbsp; };&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;&lt;STRONG&gt;LINUX sources :&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;rsyslog.conf&lt;/STRONG&gt; &lt;/FONT&gt;:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt; /etc/rsyslog.conf&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;I managed to retrieve my data in Splunk, except that the tag appears at the start of the log like this; I found a way to remove it via the props.conf file on my TA:&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anissabnk_0-1777476344743.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41994i0B8FBD21D517EAC6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anissabnk_0-1777476344743.png" alt="anissabnk_0-1777476344743.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT color="#000000"&gt;# (EXTERNE, INTERNE, RIE, CLE)SEDCMD-remove_tag = s/^(EXTERNE|INTERNE|RIE|CLE)\s+//&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anissabnk_3-1777475785732.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41993i4DA863D0FE3B5EAC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anissabnk_3-1777475785732.png" alt="anissabnk_3-1777475785732.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So, great, the tag has been removed, but the parsing isn’t working for the timestamp.&lt;BR /&gt;The _time isn’t being parsed correctly; no matter how I modify props.conf, it doesn’t work. In terms of priority, _time is parsed before SDCMD.&lt;BR /&gt;So I tried treating the tag as if it were still there in order to parse the _time.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;# Note: Extending Splunk default settings (See $SPLUNK_HOME/etc/system/default/props.conf&lt;BR /&gt;pulldown_type = 0&lt;/P&gt;&lt;P&gt;# Ignore le tag (EXTERNE/INTERNE/RIE/CLE) et pointe sur le timestamp&lt;BR /&gt;TIME_PREFIX = ^(?:EXTERNE|INTERNE|RIE|CLE)\s+&lt;/P&gt;&lt;P&gt;# Format du timestamp : "Apr 28 10:45:00"&lt;BR /&gt;TIME_FORMAT = %b %d %H:%M:%S&lt;/P&gt;&lt;P&gt;# Augmente la fenêtre de recherche pour inclure le timestamp + nom d'hôte&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 25&lt;/P&gt;&lt;P&gt;# Désactive la fusion de lignes&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;# Extract the subject if enabled in Postfix's configuration&lt;BR /&gt;REPORT-subject = postfix_subject&lt;BR /&gt;# Extract to/from/message-id/helo (without the '&amp;lt;&amp;gt;'s)&lt;BR /&gt;REPORT-angle_brackets = postfix_angle_brackets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get the feeling the problem lies with sc4s, and that I might need to add something to rsyslog.conf, but I’m not sure how to go about it.&lt;/P&gt;&lt;P&gt;Can you help me?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 15:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760565#M24184</guid>
      <dc:creator>anissabnk</dc:creator>
      <dc:date>2026-04-29T15:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760568#M24185</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231839"&gt;@anissabnk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using SC4S then you'll be sending the data to Splunk HEC, depending on the endpoint this may be as a parsed event rather than a raw event, in which case the timestamp extraction wont happen because it doesnt hit that pipeline, however...you could try adding this to your props/transforms:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# props.conf
[yourSourcetype]
TRANSFORMS-getCorrectSC4STime = getCorrectSC4STime

# transforms
[getCorrectSC4STime]
INGEST_EVAL = _time=strptime(_raw,"%B %d %H:%M:%S")&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 19:55:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760568#M24185</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-04-29T19:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760575#M24186</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;, I tried what you propose but unfortunately, it doesn't work :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anissabnk_0-1777536752909.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41995i13DAB5653DE076C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anissabnk_0-1777536752909.png" alt="anissabnk_0-1777536752909.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That's what I did, on my .conf files :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;&lt;STRONG&gt;props.conf :&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;# KSCONF-NO-SORT&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[st_postfix]&lt;/P&gt;&lt;P&gt;# Note: Extending Splunk default settings (See $SPLUNK_HOME/etc/system/default/props.conf&lt;BR /&gt;pulldown_type = 0&lt;/P&gt;&lt;P&gt;# Ignore le tag (EXTERNE/INTERNE/RIE/CLE) et pointe sur le timestamp&lt;BR /&gt;TIME_PREFIX = ^(?:EXTERNE|INTERNE|RIE|CLE)\s+&lt;/P&gt;&lt;P&gt;# Format du timestamp : "Apr 28 10:45:00"&lt;BR /&gt;TIME_FORMAT = %b %d %H:%M:%S&lt;/P&gt;&lt;P&gt;# Augmente la fenêtre de recherche pour inclure le timestamp + nom d'hôte&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 25&lt;/P&gt;&lt;P&gt;# Désactive la fusion de lignes&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;# Extract the subject if enabled in Postfix's configuration&lt;BR /&gt;REPORT-subject = postfix_subject&lt;BR /&gt;# Extract to/from/message-id/helo (without the '&amp;lt;&amp;gt;'s)&lt;BR /&gt;REPORT-angle_brackets = postfix_angle_brackets&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;EXTRACT-queue_id = postfix/[\w/]+\[\d+\]:\s+(?&amp;lt;queue_id&amp;gt;[A-Fa-f0-9]{6,20}):&lt;BR /&gt;EXTRACT-bounce = postfix/bounce\[\d+\]: [a-fA-F0-9]{6,20}: (?&amp;lt;bounce_reason&amp;gt;[^:]+): (?&amp;lt;bounce_queue_id&amp;gt;[a-fA-F0-9]{6,20})$&lt;BR /&gt;EXTRACT-status_reject = postfix/smtpd\[\d+\]: (?:NOQUEUE|[A-Fa-f0-9]{6,20}): (?&amp;lt;status&amp;gt;reject):&lt;BR /&gt;EXTRACT-reason = status=[^\s]+\s+\((?&amp;lt;reason&amp;gt;.*)\)$&lt;BR /&gt;EXTRACT-reject_reason = : (?&amp;lt;reject_reason&amp;gt;[^;:]+);&lt;BR /&gt;EXTRACT-dest = relay=(?&amp;lt;dest_host&amp;gt;[^\[ ,]+)\[(?&amp;lt;dest_ip&amp;gt;[^: \]]+)\](?::(?&amp;lt;dest_port&amp;gt;\d+))?&lt;BR /&gt;EXTRACT-remote_queue = queued as (?&amp;lt;xref&amp;gt;[A-Fa-f0-9]+) in reason&lt;BR /&gt;EXTRACT-status_code = status=\w+ \((?:host \S+ said:\s*)?(?&amp;lt;status_code_short&amp;gt;\d+)&lt;BR /&gt;EXTRACT-src-connect = (?:dis)?connect(?:ion after (?:HELO|CONNECT))? from (?:(?&amp;lt;src_host&amp;gt;[^\[]+)\[(?&amp;lt;src_ip&amp;gt;[\d.]+)|(?&amp;lt;src&amp;gt;.*))&lt;BR /&gt;# Extration of the different delays (cf. &lt;A href="http://logreporters.sourceforge.net/faq.html#percentiles" target="_blank"&gt;http://logreporters.sourceforge.net/faq.html#percentiles&lt;/A&gt;)&lt;BR /&gt;EXTRACT-delays = ^(?&amp;lt;time_before_queue&amp;gt;[^/]+)/(?&amp;lt;time_in_queue&amp;gt;[^/]+)/(?&amp;lt;time_connecting&amp;gt;[^/]+)/(?&amp;lt;time_transmitting&amp;gt;[^$]+)$ in delays&lt;/P&gt;&lt;P&gt;# Rename fields for CIM compliance with the Email data model&lt;BR /&gt;FIELDALIAS-status_code = dsn as status_code&lt;BR /&gt;#FIELDALIAS-status_code = status_code_short as status_code&lt;BR /&gt;FIELDALIAS-protocol = proto as protocol&lt;BR /&gt;FIELDALIAS-filter_action = reject_reason as filter_action&lt;BR /&gt;FIELDALIAS-internal_message_id = queue_id AS internal_message_id&lt;BR /&gt;FIELDALIAS-process_id = pid AS process_id&lt;BR /&gt;FIELDALIAS-src_user = from as src_user&lt;BR /&gt;FIELDALIAS-recipient = to as recipient&lt;BR /&gt;FIELDALIAS-orig_recipient = orig_to as orig_recipient&lt;BR /&gt;FIELDALIAS-recipient_count = nrcpt as recipient_count&lt;/P&gt;&lt;P&gt;# Don't extract 'src_host' if "unknown" (typical with reverse DNS disabled)&lt;BR /&gt;EVAL-src=coalesce(src, nullif(src_host, "unknown"), src_ip)&lt;BR /&gt;# FIELDALIAS-src=src_host AS src, src_ip AS src&lt;BR /&gt;EVAL-dest = coalesce(dest, nullif(dest_host, "unknown"), dest_ip)&lt;/P&gt;&lt;P&gt;LOOKUP-consts = postfix_consts sourcetype OUTPUT protocol, vendor, product&lt;BR /&gt;LOOKUP-actions = postfix_actions status OUTPUT action&lt;/P&gt;&lt;P&gt;# Email CIM requires the delay field to be in milliseconds&lt;BR /&gt;EVAL-delay = delay*1000&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# Suppression des tags injectés par rsyslog (EXTERNE, INTERNE, RIE, CLE)&lt;BR /&gt;SEDCMD-remove_tag = s/^(EXTERNE|INTERNE|RIE|CLE)\s+//&lt;/P&gt;&lt;P&gt;#Extraction du _time&lt;BR /&gt;TRANSFORMS-getCorrectSC4STime = getCorrectSC4STime&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;U&gt;&lt;STRONG&gt;transforms.conf :&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;# KSCONF-NO-SORT&lt;/P&gt;&lt;P&gt;[postfix_angle_brackets]&lt;BR /&gt;# Strip out the '&amp;lt;' or '&amp;gt;' from the value of the postfix log messages.&lt;BR /&gt;# Examples:&lt;BR /&gt;# to=&amp;lt;jdoe@aol.com&amp;gt;&lt;BR /&gt;# from=&amp;lt;bob@example.com&amp;gt;&lt;BR /&gt;# message-id=&amp;lt;20360611180017.4944318FE39@webapp.example.com&amp;gt;&lt;BR /&gt;# helo=&amp;lt;localhost.localdomain&amp;gt;&lt;BR /&gt;REGEX = [ ](to|from|message-id|helo)=&amp;lt;([^&amp;lt;&amp;gt; ]+)&amp;gt;&lt;BR /&gt;FORMAT = $1::$2&lt;/P&gt;&lt;P&gt;[postfix_subject]&lt;BR /&gt;# Logging the subject header requires changes to postfix config (disabled by default)&lt;BR /&gt;# main.cf: header_checks = regexp:/etc/postfix/header_checks&lt;BR /&gt;# header_checks: /^subject:/ WARN&lt;BR /&gt;# Example event:&lt;BR /&gt;# Nov 4 10:57:01 localhost postfix/cleanup[22492]: 2290326720: warning: header subject: test email from localhost[127.0.0.1]; from= to= proto=SMTP helo=&lt;BR /&gt;REGEX = header [Ss]ubject: (?&amp;lt;subject&amp;gt;.+?) from [^;]+;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# Lookups&lt;/P&gt;&lt;P&gt;[postfix_consts]&lt;BR /&gt;# Constant fields applied uniformly to ALL events&lt;BR /&gt;# Note: More efficient than using an 'EVAL-*' for these fields.&lt;BR /&gt;filename = postfix_consts.csv&lt;/P&gt;&lt;P&gt;[postfix_actions]&lt;BR /&gt;# Convert Postfix's 'status' messages into CIM 'actions' (as best as possible)&lt;BR /&gt;filename = postfix_actions.csv&lt;/P&gt;&lt;P&gt;#Extraction du _time&lt;BR /&gt;[getCorrectSC4STime]&lt;BR /&gt;INGEST_EVAL = _time=strptime(_raw,"%B %d %H:%M:%S")&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 08:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760575#M24186</guid>
      <dc:creator>anissabnk</dc:creator>
      <dc:date>2026-04-30T08:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760577#M24188</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231839"&gt;@anissabnk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;may i know, after updating&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;'s props and transforms, did you restart the Splunk Service&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;/P&gt;&lt;P&gt;PS - As of Apr 2026, my Karma Given is 2290 and my Karma Received is 494, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 10:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760577#M24188</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-04-30T10:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760582#M24191</link>
      <description>&lt;P class="lia-align-left"&gt;Yes, of course, I restarted splunk, but it doesn't work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 12:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760582#M24191</guid>
      <dc:creator>anissabnk</dc:creator>
      <dc:date>2026-04-30T12:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760584#M24193</link>
      <description>&lt;P&gt;Ok Sure&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231839"&gt;@anissabnk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next, lets check what props and transforms are being applied.&lt;/P&gt;&lt;P&gt;Could you pls try:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;splunk btool props list &amp;lt;sourcetype&amp;gt; --debug&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;splunk btool transforms list &amp;lt;transform_name&amp;gt; --debug&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;BR /&gt;&lt;BR /&gt;PS - As of Apr 2026, my Karma Given is 2290 and my Karma Received is 494, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 30 Apr 2026 13:50:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760584#M24193</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-04-30T13:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: extract time with sc4s</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760657#M24213</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;For the sourcetype, that's what I obtain :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;[splunk@splunk ~]$ /opt/splunk/bin/splunk btool props list st_postfix --debug&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf [st_postfix]&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf ADD_EXTRA_TIME_FIELDS = True&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf ANNOTATE_PUNCT = True&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf AUTO_KV_JSON = true&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE =&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf CHARSET = UTF-8&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf DATETIME_CONFIG = /etc/datetime.xml&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf DEPTH_LIMIT = 1000&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = false&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EVAL-delay = delay*1000&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EVAL-dest = coalesce(dest, nullif(dest_host, "unknown"), dest_ip)&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EVAL-src=coalesce(src, nullif(src_host, "unknown"), src_ip)&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-bounce = postfix/bounce\[\d+\]: [a-fA-F0-9]{6,20}: (?&amp;lt;bounce_reason&amp;gt;[^:]+): (?&amp;lt;bounce_queue_id&amp;gt;[a-fA-F0-9]{6,20})$&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-delays = ^(?&amp;lt;time_before_queue&amp;gt;[^/]+)/(?&amp;lt;time_in_queue&amp;gt;[^/]+)/(?&amp;lt;time_connecting&amp;gt;[^/]+)/(?&amp;lt;time_transmitting&amp;gt;[^$]+)$ in delays&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-dest = relay=(?&amp;lt;dest_host&amp;gt;[^\[ ,]+)\[(?&amp;lt;dest_ip&amp;gt;[^: \]]+)\](?::(?&amp;lt;dest_port&amp;gt;\d+))?&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-queue_id = postfix/[\w/]+\[\d+\]:\s+(?&amp;lt;queue_id&amp;gt;[A-Fa-f0-9]{6,20}):&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-reason = status=[^\s]+\s+\((?&amp;lt;reason&amp;gt;.*)\)$&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-reject_reason = : (?&amp;lt;reject_reason&amp;gt;[^;:]+);&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-remote_queue = queued as (?&amp;lt;xref&amp;gt;[A-Fa-f0-9]+) in reason&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-src-connect = (?:dis)?connect(?:ion after (?:HELO|CONNECT))? from (?:(?&amp;lt;src_host&amp;gt;[^\[]+)\[(?&amp;lt;src_ip&amp;gt;[\d.]+)|(?&amp;lt;src&amp;gt;.*))&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-status_code = status=\w+ \((?:host \S+ said:\s*)?(?&amp;lt;status_code_short&amp;gt;\d+)&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf EXTRACT-status_reject = postfix/smtpd\[\d+\]: (?:NOQUEUE|[A-Fa-f0-9]{6,20}): (?&amp;lt;status&amp;gt;reject):&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-filter_action = reject_reason as filter_action&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-internal_message_id = queue_id AS internal_message_id&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-orig_recipient = orig_to as orig_recipient&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-process_id = pid AS process_id&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-protocol = proto as protocol&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-recipient = to as recipient&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-recipient_count = nrcpt as recipient_count&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-src_user = from as src_user&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf FIELDALIAS-status_code = dsn as status_code&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf HEADER_MODE =&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf LB_CHUNK_BREAKER_TRUNCATE = 2000000&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf LEARN_MODEL = true&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf LEARN_SOURCETYPE = true&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf LOOKUP-actions = postfix_actions status OUTPUT action&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf LOOKUP-consts = postfix_consts sourcetype OUTPUT protocol, vendor, product&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MATCH_LIMIT = 100000&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MAX_DAYS_AGO = 2000&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MAX_DAYS_HENCE = 2&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MAX_EVENTS = 256&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MAX_EXPECTED_EVENT_LINES = 7&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf MAX_TIMESTAMP_LOOKAHEAD = 25&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MUST_BREAK_AFTER =&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_AFTER =&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_BEFORE =&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf REPORT-angle_brackets = postfix_angle_brackets&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf REPORT-subject = postfix_subject&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf SEDCMD-remove_tag = s/^(EXTERNE|INTERNE|RIE|CLE)\s+//&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf SEGMENTATION = indexing&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf SEGMENTATION-all = full&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf SEGMENTATION-inner = inner&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf SEGMENTATION-outer = outer&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf SEGMENTATION-raw = none&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf SEGMENTATION-standard = standard&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf SHOULD_LINEMERGE = false&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf TIME_FORMAT = %b %d %H:%M:%S&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf TIME_PREFIX = ^(?:EXTERNE|INTERNE|RIE|CLE)\s+&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf TRANSFORMS =&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf TRUNCATE = 10000&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf detect_trailing_nulls = false&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf maxDist = 100&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf priority =&lt;BR /&gt;/opt/splunk/etc/apps/TA-postfix/local/props.conf pulldown_type = 0&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf sourcetype =&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf termFrequencyWeightedDist = false&lt;BR /&gt;/opt/splunk/etc/system/default/props.conf unarchive_cmd_start_mode = shell&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 14:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/extract-time-with-sc4s/m-p/760657#M24213</guid>
      <dc:creator>anissabnk</dc:creator>
      <dc:date>2026-05-04T14:34:24Z</dc:date>
    </item>
  </channel>
</rss>

