<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic timestamp issues with threatconnect TA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-issues-with-threatconnect-TA/m-p/578543#M102156</link>
    <description>&lt;P&gt;Good Afternoon,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I am having an issue with the ThreatConnect TA. The API appears to be connecting as expected but no logs are in the index. I observed within splunkd.log the log sample found below. Looking at the props.conf, it appears it is configured correctly. has anyone had this issue? it appears the logs are in epoch time.&lt;/P&gt;&lt;P&gt;12-15-2021 20:36:44.013 +0000 WARN DateParserVerbose [38565 merging_1] - The TIME_FORMAT specified is matching timestamps (INVALID_TIME (1639600603907184)) outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source=tc_download_indicators.py|host=127.0.0.1|threatconnect-app-logs|10128188&lt;/P&gt;&lt;P&gt;PROPS.CONF config&lt;/P&gt;&lt;P&gt;[threatconnect-app-logs]&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;TIMESTAMP_FIELDS = timestamp&lt;BR /&gt;TIME_FORMAT = %s.%6N&lt;BR /&gt;category = Application&lt;BR /&gt;description = ThreatConnect App Logs&lt;BR /&gt;pulldown_type = 1&lt;/P&gt;&lt;P&gt;[threatconnect-event-data]&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;TIMESTAMP_FIELDS = timestamp&lt;BR /&gt;TIME_FORMAT = %s.%6N&lt;BR /&gt;category = Application&lt;BR /&gt;description = ThreatConnect Matched Event Data&lt;BR /&gt;pulldown_type = 1&lt;/P&gt;&lt;P&gt;[source::...tc_ar_send_to_playbook.log*]&lt;BR /&gt;sourcetype = send_event_to_threatconnect_playbook:*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Dec 2021 20:46:28 GMT</pubDate>
    <dc:creator>jerm1020rq</dc:creator>
    <dc:date>2021-12-15T20:46:28Z</dc:date>
    <item>
      <title>timestamp issues with threatconnect TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-issues-with-threatconnect-TA/m-p/578543#M102156</link>
      <description>&lt;P&gt;Good Afternoon,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I am having an issue with the ThreatConnect TA. The API appears to be connecting as expected but no logs are in the index. I observed within splunkd.log the log sample found below. Looking at the props.conf, it appears it is configured correctly. has anyone had this issue? it appears the logs are in epoch time.&lt;/P&gt;&lt;P&gt;12-15-2021 20:36:44.013 +0000 WARN DateParserVerbose [38565 merging_1] - The TIME_FORMAT specified is matching timestamps (INVALID_TIME (1639600603907184)) outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source=tc_download_indicators.py|host=127.0.0.1|threatconnect-app-logs|10128188&lt;/P&gt;&lt;P&gt;PROPS.CONF config&lt;/P&gt;&lt;P&gt;[threatconnect-app-logs]&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;TIMESTAMP_FIELDS = timestamp&lt;BR /&gt;TIME_FORMAT = %s.%6N&lt;BR /&gt;category = Application&lt;BR /&gt;description = ThreatConnect App Logs&lt;BR /&gt;pulldown_type = 1&lt;/P&gt;&lt;P&gt;[threatconnect-event-data]&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;TIMESTAMP_FIELDS = timestamp&lt;BR /&gt;TIME_FORMAT = %s.%6N&lt;BR /&gt;category = Application&lt;BR /&gt;description = ThreatConnect Matched Event Data&lt;BR /&gt;pulldown_type = 1&lt;/P&gt;&lt;P&gt;[source::...tc_ar_send_to_playbook.log*]&lt;BR /&gt;sourcetype = send_event_to_threatconnect_playbook:*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 20:46:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-issues-with-threatconnect-TA/m-p/578543#M102156</guid>
      <dc:creator>jerm1020rq</dc:creator>
      <dc:date>2021-12-15T20:46:28Z</dc:date>
    </item>
  </channel>
</rss>

