<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Could not use striptime to parse timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634904#M108643</link>
    <description>&lt;P&gt;What do you mean by "could not use"?&amp;nbsp; What exactly is the problem you are having with it?&amp;nbsp; You are aware the function is pronounced "striptime", but is typed "strptime", right?&amp;nbsp; Please show the SPL you tried and the results it gave.&amp;nbsp; Also, your props.conf settings have no effect on the &lt;FONT face="courier new,courier"&gt;stptime&lt;/FONT&gt; function.&lt;/P&gt;&lt;P&gt;The LINE_BREAKER setting does not match the sample data.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE BREAKER = ()\s*("log":&lt;/LI-CODE&gt;&lt;P&gt;should be enough.&lt;/P&gt;&lt;P&gt;The TIME_FORMAT setting doesn't match the example event.&amp;nbsp; It specifies the time zone offset rather than a time zone abbreviation.&amp;nbsp; Try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME FORMAT = %Y-%m-%dT%H:%M:%S.9N%Z&lt;/LI-CODE&gt;&lt;P&gt;The first timestamp in the example log has a different format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2023 12:42:27 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-03-17T12:42:27Z</dc:date>
    <item>
      <title>Could not use striptime to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634883#M108638</link>
      <description>&lt;P&gt;Having problem creating a props configuration&lt;/P&gt;&lt;P&gt;Seeing could not use striptime to parse timestamp.&lt;/P&gt;&lt;P&gt;Below logs comes from Docker&amp;nbsp;&lt;/P&gt;&lt;P&gt;("log":"[20:52:02] [/home/a153509/.local/share/code-server/extensions/ms-toolsai.jupyter-2022.9.1303220346]: Extension is not compatible with Code 1.66.2 . Extension requires: 1.72.0.\n","stream":"stderr","time":"2023-03-06T20:52:02.2194402152"}{"log":"[20:52:02] [ /home/a15 3509/.local/share/code-server/extensions/ms-python.vscode-pylance-2023. 1.10]: Extension is not compatible with Code 1.66.2. Extension req uires: 1.67.0.\n ", "stream":"stderr","time": "2023-03-06T20:52:02.219891147Z")("log": "[20:52:02] [\u003cunknown\u003e][80d9f7e6][ Extension HostConnection] New connection established.\n","stream":"stdout","time":"2023-03-06T20:52:02.604222684Z"){"log":"[20:52:02] [ \u003cunknow n\u003e][80d9f7e6][ExtensionHostConnection] \u003c1453\u003e Launched Extension Host Process. \n","stream":"stdout","time":"2023-03-06T20: 52:02.617643295Z"] ["log": "[IPC Library: Pty Host] INFO Persistent process "1": Replaying 505 chars and 1 size events\n","stream":"stdo ut", "time":"2023-03-06T20 :52:06.9 270320622"} ["log":"[IPC Library: Pty Host] WARN Shell integration cannot be enabled for executable \"/b in/bash and args undefined\n", "stream":"stdout","time": "2023-03-06T20:52:56.754368802Z"}{ log":"[20:57:00] [\u003cunknown\u003e][laf3f4 9a][ExtensionHostConnection] \u003c766\u003e Extension Host Process exited with code: 0 , signal: null.\n","stream"stdout", "time":"2023- 03-06T20:57:00 839578031Z"}"log" [02:12:50] [\u003cunknown\u003e][adf26d01 ][ManagementConnection] The client has disconnected, will wai t for reconnection 3h before disposing...\n","stream":"stdout, "time":"2023-03-07T02:12:50. 7892555182")("log":"[05:12:59] [\u003cunknown \u003e][adf26d01][ManagementConnection] The reconnection grace time of 3h has expired, so the connection will be disposed. \n", "stream ":"s tdout","time":"2023-03-07T05:12:59.567198587Z" log":[13:16:53] [\u003cunknown\u003e][adf26d01][ManagementConnection] Unknown reconnect ion token ( seen before) \n","stream":"stderr","time":"2023-03-07T13:16:53 2951627292")("log":"[13:16:53] [\u003cunknown\u003e ][80d9f7e6] [ExtensionHostConnection] The client has reconnected. \n","stream":"stdout", "time": "2023-03-07T13: 16:53.453120386Z")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hers is my props.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;auto learned&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;SHOULD LINEMERGE=false&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;LINE BREAKER=([\n\r]+)\s*("log":"{\n&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;NO BINARY CHECK-true TIME PREFIX="time"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MAX TIMESTAMP LOOKAHEAD=48&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TIME FORMAT=%Y-%m-%dT%H:%M:%S.9N%z&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;TRUNCATE=999999&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CHARSET=UTF-8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;KV MODE=json&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;ANNOTATE POINT=false&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 08:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634883#M108638</guid>
      <dc:creator>Jackinout9</dc:creator>
      <dc:date>2023-03-17T08:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Could not use striptime to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634899#M108642</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me on above one&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 11:18:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634899#M108642</guid>
      <dc:creator>Jackinout9</dc:creator>
      <dc:date>2023-03-17T11:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Could not use striptime to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634904#M108643</link>
      <description>&lt;P&gt;What do you mean by "could not use"?&amp;nbsp; What exactly is the problem you are having with it?&amp;nbsp; You are aware the function is pronounced "striptime", but is typed "strptime", right?&amp;nbsp; Please show the SPL you tried and the results it gave.&amp;nbsp; Also, your props.conf settings have no effect on the &lt;FONT face="courier new,courier"&gt;stptime&lt;/FONT&gt; function.&lt;/P&gt;&lt;P&gt;The LINE_BREAKER setting does not match the sample data.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE BREAKER = ()\s*("log":&lt;/LI-CODE&gt;&lt;P&gt;should be enough.&lt;/P&gt;&lt;P&gt;The TIME_FORMAT setting doesn't match the example event.&amp;nbsp; It specifies the time zone offset rather than a time zone abbreviation.&amp;nbsp; Try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME FORMAT = %Y-%m-%dT%H:%M:%S.9N%Z&lt;/LI-CODE&gt;&lt;P&gt;The first timestamp in the example log has a different format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 12:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634904#M108643</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-17T12:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Could not use striptime to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634916#M108647</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried that configuration, which you suggested above.&lt;/P&gt;&lt;P&gt;Now I'll try to explain what the problem is..&lt;/P&gt;&lt;P&gt;We are trying to writing the props to onboard the docker logs.&lt;/P&gt;&lt;P&gt;The log like below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;("log":"[20:52:02] [/home/a153509/.local/share/code-server/extensions/ms-toolsai.jupyter-2022.9.1303220346]: Extension is not compatible with Code 1.66.2 . Extension requires: 1.72.0.\n","stream":"stderr","time":"2023-03-06T20:52:02.2194402152"}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While applying the props configuration it is showing some warning error like&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could not use strptime to parse timestamp from ""."[20:52:02][/home/a153509/.local/share/code-s".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 14:18:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634916#M108647</guid>
      <dc:creator>Jackinout9</dc:creator>
      <dc:date>2023-03-17T14:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Could not use striptime to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634919#M108649</link>
      <description>&lt;P&gt;It looks like Splunk is treating "20:52:02" as a timestamp rather than looking the time field later in the event.&amp;nbsp; This usually means the TIME_PREFIX field is missing or is incorrect.&amp;nbsp; In the OP, the TIME_PREFIX setting was not on a line by itself, which I thought was an error in writing the message.&amp;nbsp; Please verify the setting is correctly placed in props.conf.&lt;/P&gt;&lt;P&gt;Avoid auto-learned sourcetypes since that means Splunk made assumptions about the sourcetype and those assumptions could be incorrect.&amp;nbsp; Always specify a sourcetype in inputs.conf and have a stanza for that sourcetype in props.conf.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 14:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-use-striptime-to-parse-timestamp/m-p/634919#M108649</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-17T14:25:25Z</dc:date>
    </item>
  </channel>
</rss>

