<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why do the indexed files still have the wrong timestamp after editing the props.conf file? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587242#M103163</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I can't get Splunk to use&amp;nbsp; the content of&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;timestamp_start&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;as&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;_time&lt;/EM&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is an example of log:&lt;/SPAN&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;canale=&amp;lt;value&amp;gt;;an=&amp;lt;value&amp;gt;;num_fattura=&amp;lt;value&amp;gt;;data_emissione=2022-01-01;timestamp_start=2022-03-02&amp;nbsp;11:22:00;timestamp_end=2022-03-02&amp;nbsp;11:22:02;total_time=1.56035;http_code=200;purl=&amp;lt;value&amp;gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and this is what I get as _time&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;2022-01-01&amp;nbsp;11:22:00&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I found a configuration that should work so I edited the props.conf file on the deployment server but even if I can see the "new" props.conf on the forwarder and on the deployment server, new indexed files still have the wrong timestamp.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[my_sourcetype]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SHOULD_LINEMERGE=false&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NO_BINARY_CHECK=true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;TIME_PREFIX=.*\d*-\d*-\d*\;timestamp_start=&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;MAX_TIMESTAMP_LOOKAHEAD=19&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After editing the props.conf, I reloaded the deployment server (splunk reload deploy-server) and then I restarted Splunk on the deployment server and on the forwarder.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;My Splunk version is&amp;nbsp;&lt;SPAN&gt;6.5.1.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for any help you may be able to give me!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Mar 2022 00:13:23 GMT</pubDate>
    <dc:creator>sara_papa</dc:creator>
    <dc:date>2022-03-03T00:13:23Z</dc:date>
    <item>
      <title>Why do the indexed files still have the wrong timestamp after editing the props.conf file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587242#M103163</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I can't get Splunk to use&amp;nbsp; the content of&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;timestamp_start&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;as&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;_time&lt;/EM&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is an example of log:&lt;/SPAN&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;canale=&amp;lt;value&amp;gt;;an=&amp;lt;value&amp;gt;;num_fattura=&amp;lt;value&amp;gt;;data_emissione=2022-01-01;timestamp_start=2022-03-02&amp;nbsp;11:22:00;timestamp_end=2022-03-02&amp;nbsp;11:22:02;total_time=1.56035;http_code=200;purl=&amp;lt;value&amp;gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and this is what I get as _time&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;2022-01-01&amp;nbsp;11:22:00&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I found a configuration that should work so I edited the props.conf file on the deployment server but even if I can see the "new" props.conf on the forwarder and on the deployment server, new indexed files still have the wrong timestamp.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[my_sourcetype]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SHOULD_LINEMERGE=false&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NO_BINARY_CHECK=true&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;TIME_PREFIX=.*\d*-\d*-\d*\;timestamp_start=&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;MAX_TIMESTAMP_LOOKAHEAD=19&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After editing the props.conf, I reloaded the deployment server (splunk reload deploy-server) and then I restarted Splunk on the deployment server and on the forwarder.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;My Splunk version is&amp;nbsp;&lt;SPAN&gt;6.5.1.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for any help you may be able to give me!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 00:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587242#M103163</guid>
      <dc:creator>sara_papa</dc:creator>
      <dc:date>2022-03-03T00:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Edit props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587245#M103165</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243533"&gt;@sara_papa&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well,&lt;/P&gt;&lt;P&gt;try to set your props.conf on the indexer, I think the best way is build a small app to deploy on your indexer.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 14:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587245#M103165</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2022-03-02T14:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Edit props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587247#M103167</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243533"&gt;@sara_papa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;probably you well know that 6.5.1 isn't a supported version of Splunk!&lt;/P&gt;&lt;P&gt;Anyway, the timestamp parsing is done on the Indexers or, when present, on Heavy Forwarders, not on Universal Forwarder.&lt;/P&gt;&lt;P&gt;So you should put the props.conf to parse your logs in a TA to install on Indexers.&lt;/P&gt;&lt;P&gt;Anyway, try only a simple update to your props.conf, escaping "="&amp;nbsp;because it's a special char.:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX = timestamp_start\=&lt;/LI-CODE&gt;&lt;P&gt;Anyway, as I said, I think that the problem is in the location of your props.conf.&lt;/P&gt;&lt;P&gt;You have to put props on Forwarders only if you have an INDEXED_EXTRACTION.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 14:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-the-indexed-files-still-have-the-wrong-timestamp-after/m-p/587247#M103167</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-02T14:54:55Z</dc:date>
    </item>
  </channel>
</rss>

