<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to compose the _time in index time from two JSON fields? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/how-to-compose-the-time-in-index-time-from-two-JSON-fields/m-p/450916#M8180</link>
    <description>&lt;P&gt;I am developing a Python add-on and I am trying to specify a  &lt;CODE&gt;_time&lt;/CODE&gt; composed by two JSON fields &lt;CODE&gt;lastTstamp&lt;/CODE&gt; and &lt;CODE&gt;lastDate&lt;/CODE&gt; in the &lt;CODE&gt;index time&lt;/CODE&gt;. Therefore, the extraction is getting a different and wrong timestamp.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;JSON input:
{    
   lastTstamp: 15:32:02Z    
   lastDate: 2015-10-23        
   id: a4ec1ba0-ab74-11e6-a19f-0a7e67dda05f    
   status: new
}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;event output: &lt;CODE&gt;_time: 2015-11-18T05:55:58.000+00:00&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;So far I tried two approaches:&lt;BR /&gt;
1st approach: Using &lt;CODE&gt;helper.new_event&lt;/CODE&gt; + &lt;CODE&gt;ew.write_event(event)&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;utc_dt = datetime.strptime(data_json['lastDate'] + 'T' + data_json['lastTstamp'], '%Y-%m-%dT%H:%M:%SZ')

event = helper.new_event(time=time.mktime(utc_dt.timetuple()),
                                     source=helper.get_input_type(),
                                     index=helper.get_output_index(),
                                     sourcetype=helper.get_sourcetype(),
                                     data=json.dumps(data_json))
ew.write_event(event)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2nd approach: Edit &lt;CODE&gt;props.conf&lt;/CODE&gt; and &lt;CODE&gt;transforms.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;transform.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[alert_time]
REGEX = 'lastDate': u'(\d{4}-\d{2}-\d{2}).*lastTstamp': u'(\d{2}:\d{2}:\d{2})
FORMAT = $1T$2.000+00:00
DEST_KEY = _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [json_alert]
KV_MODE = json
SHOULD_LINEMERGE = 0
category = Splunk App Add-on Builder
pulldown_type = 1
TRANSFORMS-datetime = alert_time`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I some cases a time zone difference is expected as normal, but as depicted in the example above, there is a huge gap between input and output timestamp.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jul 2018 16:44:28 GMT</pubDate>
    <dc:creator>edigilink</dc:creator>
    <dc:date>2018-07-18T16:44:28Z</dc:date>
    <item>
      <title>how to compose the _time in index time from two JSON fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/how-to-compose-the-time-in-index-time-from-two-JSON-fields/m-p/450916#M8180</link>
      <description>&lt;P&gt;I am developing a Python add-on and I am trying to specify a  &lt;CODE&gt;_time&lt;/CODE&gt; composed by two JSON fields &lt;CODE&gt;lastTstamp&lt;/CODE&gt; and &lt;CODE&gt;lastDate&lt;/CODE&gt; in the &lt;CODE&gt;index time&lt;/CODE&gt;. Therefore, the extraction is getting a different and wrong timestamp.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;JSON input:
{    
   lastTstamp: 15:32:02Z    
   lastDate: 2015-10-23        
   id: a4ec1ba0-ab74-11e6-a19f-0a7e67dda05f    
   status: new
}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;event output: &lt;CODE&gt;_time: 2015-11-18T05:55:58.000+00:00&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;So far I tried two approaches:&lt;BR /&gt;
1st approach: Using &lt;CODE&gt;helper.new_event&lt;/CODE&gt; + &lt;CODE&gt;ew.write_event(event)&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;utc_dt = datetime.strptime(data_json['lastDate'] + 'T' + data_json['lastTstamp'], '%Y-%m-%dT%H:%M:%SZ')

event = helper.new_event(time=time.mktime(utc_dt.timetuple()),
                                     source=helper.get_input_type(),
                                     index=helper.get_output_index(),
                                     sourcetype=helper.get_sourcetype(),
                                     data=json.dumps(data_json))
ew.write_event(event)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2nd approach: Edit &lt;CODE&gt;props.conf&lt;/CODE&gt; and &lt;CODE&gt;transforms.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;transform.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[alert_time]
REGEX = 'lastDate': u'(\d{4}-\d{2}-\d{2}).*lastTstamp': u'(\d{2}:\d{2}:\d{2})
FORMAT = $1T$2.000+00:00
DEST_KEY = _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [json_alert]
KV_MODE = json
SHOULD_LINEMERGE = 0
category = Splunk App Add-on Builder
pulldown_type = 1
TRANSFORMS-datetime = alert_time`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I some cases a time zone difference is expected as normal, but as depicted in the example above, there is a huge gap between input and output timestamp.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 16:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/how-to-compose-the-time-in-index-time-from-two-JSON-fields/m-p/450916#M8180</guid>
      <dc:creator>edigilink</dc:creator>
      <dc:date>2018-07-18T16:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to compose the _time in index time from two JSON fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/how-to-compose-the-time-in-index-time-from-two-JSON-fields/m-p/450917#M8181</link>
      <description>&lt;P&gt;Solved by setting DATETIME_CONFIG equals NONE in props.conf, which means the extraction will leave the event time set to whatever time was selected by the input layer.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 13:49:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/how-to-compose-the-time-in-index-time-from-two-JSON-fields/m-p/450917#M8181</guid>
      <dc:creator>edigilink</dc:creator>
      <dc:date>2018-07-20T13:49:44Z</dc:date>
    </item>
  </channel>
</rss>

