<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to fix this error: could not use the strptime to parse timestamp from “2022-26-05T11:29:57”? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-fix-this-error-could-not-use-the-strptime-to-parse/m-p/599460#M104535</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am trying to built the parsing stanza for one of the data, while testing I am getting an pop-up message stating that "could not use the strptime to parse timestamp from “2022-26-05T11:29:57”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; As soon as I apply the Time_Format stanza the Splunk is throwing the message.&amp;nbsp; I am not sure what I am missing here.&amp;nbsp;&amp;nbsp;so could you please help me resolving this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Event details:&lt;/P&gt;
&lt;P&gt;&amp;lt;Event CompactMode="1" sEventType="OpResult" dwBasicEventType="9" dwAppSpecificEventID="5000" sEventID="EVENT_ID_SCHEDULER_STARTED" sOriginatingApplicationName="RED Identity Management Console" sOriginatingApplicationComponent="Scheduler" sOriginatingApplicationVersion="5.5.3.0" sOriginatingSystem="XXXXXXXXXXXXX" sOriginatingAccount="XXXX\XXXXX" dtPostTime="2022-26-05T&lt;SPAN&gt;11:29:57&lt;/SPAN&gt;" sMessage="RED Identity Management Console (running as user XXXX\XXXXX) on system XXXXXXXXXXXXX; - background processor started"/&amp;gt;&lt;/P&gt;
&lt;P&gt;Props stanza&lt;/P&gt;
&lt;P&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;LINE_BREAKER=([\r\n]+)\&amp;lt;Event&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;TIME_PREFIX=dtPostTime\=\"&lt;BR /&gt;TIME_FORMAT=%Y-%m-%dT%H:%M:%S&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=20&lt;/P&gt;
&lt;P&gt;Event Details:&lt;/P&gt;
&lt;P&gt;[&lt;SPAN&gt;5/26/2022 4:09:55 PM UTC&lt;/SPAN&gt;] Note: Unknown provider type; cannot verify object name 'tbl_BaseJobInfo' valid for data store.&lt;/P&gt;
&lt;P&gt;Props.conf&lt;/P&gt;
&lt;P&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;LINE_BREAKER=([\r\n]+)\[\d+\/\d{2}\/\d{4}\s\d+\:\d{2}\:\d{2}\s[^\]]+\]&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;disabled=false&lt;BR /&gt;TIME_PREFIX=^\[&lt;BR /&gt;TIME_FORMAT=&lt;SPAN&gt;%m-%d-%Y&amp;nbsp;%I:%M:%S&amp;nbsp;%p&lt;/SPAN&gt; %s&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=25&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2022 18:38:02 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2022-05-26T18:38:02Z</dc:date>
    <item>
      <title>How to fix this error: could not use the strptime to parse timestamp from “2022-26-05T11:29:57”?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-fix-this-error-could-not-use-the-strptime-to-parse/m-p/599460#M104535</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am trying to built the parsing stanza for one of the data, while testing I am getting an pop-up message stating that "could not use the strptime to parse timestamp from “2022-26-05T11:29:57”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; As soon as I apply the Time_Format stanza the Splunk is throwing the message.&amp;nbsp; I am not sure what I am missing here.&amp;nbsp;&amp;nbsp;so could you please help me resolving this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Event details:&lt;/P&gt;
&lt;P&gt;&amp;lt;Event CompactMode="1" sEventType="OpResult" dwBasicEventType="9" dwAppSpecificEventID="5000" sEventID="EVENT_ID_SCHEDULER_STARTED" sOriginatingApplicationName="RED Identity Management Console" sOriginatingApplicationComponent="Scheduler" sOriginatingApplicationVersion="5.5.3.0" sOriginatingSystem="XXXXXXXXXXXXX" sOriginatingAccount="XXXX\XXXXX" dtPostTime="2022-26-05T&lt;SPAN&gt;11:29:57&lt;/SPAN&gt;" sMessage="RED Identity Management Console (running as user XXXX\XXXXX) on system XXXXXXXXXXXXX; - background processor started"/&amp;gt;&lt;/P&gt;
&lt;P&gt;Props stanza&lt;/P&gt;
&lt;P&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;LINE_BREAKER=([\r\n]+)\&amp;lt;Event&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;TIME_PREFIX=dtPostTime\=\"&lt;BR /&gt;TIME_FORMAT=%Y-%m-%dT%H:%M:%S&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=20&lt;/P&gt;
&lt;P&gt;Event Details:&lt;/P&gt;
&lt;P&gt;[&lt;SPAN&gt;5/26/2022 4:09:55 PM UTC&lt;/SPAN&gt;] Note: Unknown provider type; cannot verify object name 'tbl_BaseJobInfo' valid for data store.&lt;/P&gt;
&lt;P&gt;Props.conf&lt;/P&gt;
&lt;P&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;LINE_BREAKER=([\r\n]+)\[\d+\/\d{2}\/\d{4}\s\d+\:\d{2}\:\d{2}\s[^\]]+\]&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;disabled=false&lt;BR /&gt;TIME_PREFIX=^\[&lt;BR /&gt;TIME_FORMAT=&lt;SPAN&gt;%m-%d-%Y&amp;nbsp;%I:%M:%S&amp;nbsp;%p&lt;/SPAN&gt; %s&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=25&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 18:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-fix-this-error-could-not-use-the-strptime-to-parse/m-p/599460#M104535</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2022-05-26T18:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix this error: could not use the strptime to parse timestamp from “2022-26-05T11:29:57”</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-fix-this-error-could-not-use-the-strptime-to-parse/m-p/599482#M104541</link>
      <description>&lt;P&gt;I am not sure if this is your problem but, from the event, it looks like the second time format should be&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT=%m/%d/%Y %I:%M:%S %p %s&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 26 May 2022 18:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-fix-this-error-could-not-use-the-strptime-to-parse/m-p/599482#M104541</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-26T18:28:17Z</dc:date>
    </item>
  </channel>
</rss>

