<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are some of the Linux timestamps not parsing? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407151#M14664</link>
    <description>&lt;P&gt;solved, thanks, maybe bad copy/paste &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Mar 2019 15:34:12 GMT</pubDate>
    <dc:creator>splunkreal</dc:creator>
    <dc:date>2019-03-07T15:34:12Z</dc:date>
    <item>
      <title>Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407142#M14655</link>
      <description>&lt;H2&gt;I tried importing these on a different non production system, and some new information came to light. This post has now been heavily edited....&lt;/H2&gt;

&lt;P&gt;I recently added several servers to our splunk system, and they are all reporting as &lt;CODE&gt;sourcetype=linux_audit&lt;/CODE&gt; &lt;BR /&gt;
Looking at the logs, I am pretty sure they are from redhat (or similar).&lt;/P&gt;

&lt;P&gt;On some machines, when I go through my logs, I see that many logs from this sourcetype are using a completely inaccurate timestamp based on a different non-timey field. This is leading to about a million logs indexing in a single millisecond at the beginning of the minute.&lt;/P&gt;

&lt;P&gt;Raw log export from the "ok" logs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;type=PATH msg=audit(1534140093.101:21496165): item=0 name="/opt/dell/srvadmin/var/log/openmanage/ssclp.log" inode=1548754 dev=08:01 mode=0100600 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534140093.085:21496163): item=0 name="/opt/dell/srvadmin/var/lib/openmanage//.omaipc" inode=1556610 dev=08:01 mode=0100664 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534140086.441:21496150): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534140061.653:21496119): item=0 name="/opt/dell/srvadmin/var/log/openmanage/ssclp.log" inode=1548754 dev=08:01 mode=0100600 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534140061.569:21496113): item=0 name="/opt/dell/srvadmin/var/lib/openmanage//.omaipc" inode=1556610 dev=08:01 mode=0100664 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534140061.441:21496109): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Raw log export from the not_ok logs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;type=PATH msg=audit(1534175054.889:21553987): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534175054.885:21553986): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534175050.889:21553982): item=0 name="/bin/ping" inode=1286162 dev=08:01 mode=0104755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534175044.885:21553976): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534175036.428:21553965): item=0 name="/bin/ping" inode=1286162 dev=08:01 mode=0104755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534174959.872:21553690): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534174956.416:21553686): item=0 name="/bin/ping" inode=1286162 dev=08:01 mode=0104755 ouid=0 ogid=0 rdev=00:00
type=PATH msg=audit(1534174954.876:21553684): item=1 name=(null) inode=917506 dev=08:01 mode=0100755 ouid=0 ogid=0 rdev=00:00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Looking at those, I see no differences. BUT, splunk does!&lt;BR /&gt;
I exported these files, and went to import them into a different system and I noticed that Splunk was grabbing the timestamp from the wrong field, but only sometimes. (These "ok" and "not_ok" logs are chronologically mixed together, even if the search result says they are not)&lt;/P&gt;

&lt;P&gt;Screenshot of the "not_ok"&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5560i2BD1D1F791F0613A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Screenshot of the "ok"&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5561i75566176F08331C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 14:06:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407142#M14655</guid>
      <dc:creator>oliverj</dc:creator>
      <dc:date>2018-08-13T14:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407143#M14656</link>
      <description>&lt;P&gt;1364481363.243 is over 5 years ago, which puts it outside of Splunk's default "MAX_DAYS_AGO" limit (2000 days).&lt;/P&gt;

&lt;P&gt;Typically such logs would get passed through a syslog engine that adds a header with timestamp and host, so you could take the timestamp from there.&lt;/P&gt;

&lt;P&gt;But configuring timestamping and linebreaking in props.conf for this sourcetype should be fairly simple, right?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = msg=audit\(
MAX_TIMESTAMP_LOOKAHEAD = 25
TIME_FORMAT = %s.%3N
LINE_BREAKER = ([\r\n]+)type=\S+\s+msg=audit
SHOULD_LINEMERGE = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(this parses the &lt;CODE&gt;xxxxxxxx.xxx&lt;/CODE&gt; part as an epoch timestamp + milliseconds; not sure what the &lt;CODE&gt;:xxxxx&lt;/CODE&gt; part is about...)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407143#M14656</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2020-09-29T20:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407144#M14657</link>
      <description>&lt;P&gt;That was a sample log from redhat.&lt;BR /&gt;
I am transferring some screenshots and sample raw logs.&lt;BR /&gt;
This problem is evolving, and the screenshots should give a lot more context to my question.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 17:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407144#M14657</guid>
      <dc:creator>oliverj</dc:creator>
      <dc:date>2018-08-13T17:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407145#M14658</link>
      <description>&lt;P&gt;Updated!&lt;BR /&gt;
Hopefully that will clarify my issue.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 19:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407145#M14658</guid>
      <dc:creator>oliverj</dc:creator>
      <dc:date>2018-08-13T19:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407146#M14659</link>
      <description>&lt;P&gt;Got it, thanks for the screenshots.&lt;/P&gt;

&lt;P&gt;Not entirely sure why Splunk is behaving the way it does here. But this is a clear example of why you don't want to rely on automatic timestamping and linebreaking (your linebreaking is also failing miserably). Apart from a very significant performance impact, it also simply isn't reliable in all cases.&lt;/P&gt;

&lt;P&gt;So just define that yourself, as already sketched in my answer above. I've added linebreaking settings as well now.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 07:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407146#M14659</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-08-14T07:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407147#M14660</link>
      <description>&lt;P&gt;It actually doesn't need linebreaking!&lt;BR /&gt;
The moment I put your &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = msg=audit\(
 MAX_TIMESTAMP_LOOKAHEAD = 25
 TIME_FORMAT = %s.%3N
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;suggestion in, the linebreaks worked perfectly as did the timestamps.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 13:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407147#M14660</guid>
      <dc:creator>oliverj</dc:creator>
      <dc:date>2018-08-14T13:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407148#M14661</link>
      <description>&lt;P&gt;Glad to hear that. And yes, Splunk by default breaks before each line with a timestamp or something like that. So once it has a reliable way to determine timestamps, that also helps it determine where to break. For performance reasons it may still be useful to make that explicit as well, but getting the time  stamping set properly is I think the most important part.&lt;/P&gt;

&lt;P&gt;Please mark the answer as accepted if it works for you, so others can also find that answer easily if they run into a similar issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 13:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407148#M14661</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-08-14T13:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407149#M14662</link>
      <description>&lt;P&gt;Hello, this looks good however I'm getting error on UF 6.x when restarted :&lt;/P&gt;

&lt;P&gt;Checking conf files for problems...&lt;BR /&gt;
Bad regex value: '([\r\n]+)type=\S+\s+\msg=audit', of param: props.conf / [linux_audit] / LINE_BREAKER; why: unrecognized character follows \&lt;BR /&gt;
One or more regexes in your configuration are not valid. For details, please see btool.log or directly above.&lt;BR /&gt;
Done&lt;BR /&gt;
. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:35:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407149#M14662</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-09-29T23:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407150#M14663</link>
      <description>&lt;P&gt;Hmm, I guess that \ in front of msg= shouldn't be there. Try removing that. Not sure how I got that there.&lt;/P&gt;

&lt;P&gt;But setting LINE_BREAKER on a UF isn't very useful anyway, as that doesn't do anything with line breaking.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 15:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407150#M14663</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-07T15:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407151#M14664</link>
      <description>&lt;P&gt;solved, thanks, maybe bad copy/paste &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 15:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407151#M14664</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2019-03-07T15:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407152#M14665</link>
      <description>&lt;P&gt;Cool &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Updated it in my answer as well, in case someone else stumbles upon this post in the future &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 15:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407152#M14665</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-07T15:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the Linux timestamps not parsing?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407153#M14666</link>
      <description>&lt;P&gt;You my want to set MAX_TIMESTAMP_LOOKAHEAD = 14 &lt;BR /&gt;
The timestamp is 1534140093.101which is 14 chars after the declared TIME_PREFIX&lt;BR /&gt;
The :21496165 is a ID number&lt;/P&gt;

&lt;P&gt;see &lt;A href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-understanding_audit_log_files" target="_blank"&gt;https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-understanding_audit_log_files&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;HTH &lt;BR /&gt;
Shaky&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-some-of-the-Linux-timestamps-not-parsing/m-p/407153#M14666</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2020-09-29T23:35:42Z</dc:date>
    </item>
  </channel>
</rss>

