<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Time stamp for index time extraction in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340497#M5193</link>
    <description>&lt;P&gt;Following are the different time stamp we are getting from different sources and trying to write a time stamp for the index time extraction. Your help is much appreciated.&lt;/P&gt;

&lt;P&gt;10.10.10.10 - - [06/Mar/2017:11:45:30 +0000] "GET /service....."&lt;BR /&gt;
2017-03-05T16:03:50.457678+00:00 HOSTNAME&lt;BR /&gt;
17/3/5@13:03:01: EXIT&lt;BR /&gt;
Mar  3 16:01:34&lt;BR /&gt;
Fri Mar  3 15:54:59 2017&lt;BR /&gt;
2017-03-05 13:14:39+00000&lt;BR /&gt;
2017-03-05 15:22:39,849 &lt;/P&gt;</description>
    <pubDate>Mon, 06 Mar 2017 12:20:16 GMT</pubDate>
    <dc:creator>sreejith2k2</dc:creator>
    <dc:date>2017-03-06T12:20:16Z</dc:date>
    <item>
      <title>Time stamp for index time extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340497#M5193</link>
      <description>&lt;P&gt;Following are the different time stamp we are getting from different sources and trying to write a time stamp for the index time extraction. Your help is much appreciated.&lt;/P&gt;

&lt;P&gt;10.10.10.10 - - [06/Mar/2017:11:45:30 +0000] "GET /service....."&lt;BR /&gt;
2017-03-05T16:03:50.457678+00:00 HOSTNAME&lt;BR /&gt;
17/3/5@13:03:01: EXIT&lt;BR /&gt;
Mar  3 16:01:34&lt;BR /&gt;
Fri Mar  3 15:54:59 2017&lt;BR /&gt;
2017-03-05 13:14:39+00000&lt;BR /&gt;
2017-03-05 15:22:39,849 &lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 12:20:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340497#M5193</guid>
      <dc:creator>sreejith2k2</dc:creator>
      <dc:date>2017-03-06T12:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp for index time extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340498#M5194</link>
      <description>&lt;P&gt;Hi sreejith2k2,&lt;BR /&gt;
you can use this doc as a reference: &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Commontimeformatvariables"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;BR /&gt;
for line number 1 it will be %d/%b/%Y:%H:%M %z&lt;BR /&gt;
Hope it helps&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 13:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340498#M5194</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-03-06T13:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp for index time extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340499#M5195</link>
      <description>&lt;P&gt;Are you having more than one time format in an event for a given data source or the logs from different sources have diff time format? ( in the former, you can specific which timestamp to use for TIME_FORMAT and TIME_PREFIX. In the later, how about giving a different sourcetype to each data source and define its timestamp as per the format in the event).&lt;/P&gt;

&lt;P&gt;Pls let me know if I am missing something.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340499#M5195</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2020-09-29T13:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp for index time extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340500#M5196</link>
      <description>&lt;P&gt;Each source should have its own config settings, including timestamp and sourcetype.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 14:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340500#M5196</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-03-06T14:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp for index time extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340501#M5197</link>
      <description>&lt;P&gt;Hi sreejith2k2, First of all, you'll want to make sure that the events with these different time formats are partitioned out to their own sources and/or sourcetypes. I'd guess that Splunk can probably make sense of the timestamp for at least some of these formats.&lt;/P&gt;

&lt;P&gt;For the sources that Splunk can't recognize the timestamp for (the "Add Data" wizard is great for determining this, take a sample set of events and run it through that to immediately find out if Splunk can figure it out), you can set Props configuration on the source/sourcetype to tell Splunk some attributes concerning the timestamp in the events. See this for more details : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Data/Configuretimestamprecognition"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Data/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Essentially, you can tell Splunk the strptime format ( &lt;CODE&gt;strptime&lt;/CODE&gt; ) , you can give it a regex for a pattern that precedes the timestamp ( &lt;CODE&gt;TIME_PREFIX&lt;/CODE&gt; ), and you can tell it how many characters either into the event, or from the prefix it should look for the timestamp ( &lt;CODE&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/CODE&gt; )&lt;/P&gt;

&lt;P&gt;Also, see the "Timestamp extraction configuration" section of the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Propsconf"&gt;props.conf&lt;/A&gt; spec for a full list of available configuration directives.&lt;/P&gt;

&lt;P&gt;Please let me know if this answers your question!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 14:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Time-stamp-for-index-time-extraction/m-p/340501#M5197</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2017-03-06T14:13:23Z</dc:date>
    </item>
  </channel>
</rss>

