<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to reformat timestamp in SYSLOG _raw in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reformat-timestamp-in-SYSLOG-raw/m-p/650038#M110464</link>
    <description>&lt;P&gt;SYSLOG often sends the timestamp in the older format (e.g. Jul 11 14:23:32).&amp;nbsp; Unfortunately, that format does not have a year or timezone.&amp;nbsp; I know that Splunk has logic to 'figure' it out, but I need to have it reformatted to the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp; YYYY-MM-DDTHH:mm:ss&amp;lt;GMT offset&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to accomplish this with INGEST_EVAL or other method?&amp;nbsp; If so how is it done?&amp;nbsp; This should change the _raw event(that is, this is not a search time question).&amp;nbsp; Kind of like a mask.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2023 18:37:14 GMT</pubDate>
    <dc:creator>dokaas_2</dc:creator>
    <dc:date>2023-07-11T18:37:14Z</dc:date>
    <item>
      <title>How to reformat timestamp in SYSLOG _raw</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reformat-timestamp-in-SYSLOG-raw/m-p/650038#M110464</link>
      <description>&lt;P&gt;SYSLOG often sends the timestamp in the older format (e.g. Jul 11 14:23:32).&amp;nbsp; Unfortunately, that format does not have a year or timezone.&amp;nbsp; I know that Splunk has logic to 'figure' it out, but I need to have it reformatted to the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp; YYYY-MM-DDTHH:mm:ss&amp;lt;GMT offset&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to accomplish this with INGEST_EVAL or other method?&amp;nbsp; If so how is it done?&amp;nbsp; This should change the _raw event(that is, this is not a search time question).&amp;nbsp; Kind of like a mask.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 18:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reformat-timestamp-in-SYSLOG-raw/m-p/650038#M110464</guid>
      <dc:creator>dokaas_2</dc:creator>
      <dc:date>2023-07-11T18:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to reformat timestamp in SYSLOG _raw</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reformat-timestamp-in-SYSLOG-raw/m-p/650094#M110480</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161348"&gt;@dokaas_2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I know two solutions:&lt;/P&gt;&lt;P&gt;a pre-parsing script that reformat your logs before Splunk ingest them.&lt;/P&gt;&lt;P&gt;the SEDCMD command.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 06:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reformat-timestamp-in-SYSLOG-raw/m-p/650094#M110480</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-12T06:36:01Z</dc:date>
    </item>
  </channel>
</rss>

