<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic json in splunk is ignoring the timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/json-in-splunk-is-ignoring-the-timestamp/m-p/57574#M11248</link>
    <description>&lt;P&gt;Hi I currently have the following json in splunk:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{"first_name": "john", "last_name": "black", "timestamp": "2013-09-09 08:00:00", "age": "26", "activity": "start"}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The issue is that splunk should read the timestamp and use that for the time the event is logged. However, it simply is taking the time the event was indexed into the system instead. There is no problem with the other fields, they are parsed fine by splunk.&lt;/P&gt;

&lt;P&gt;How should I make splunk recognise the timestamp in this json? Is it possible for it to be done automatically if the format the timestamp is written in it changed?&lt;/P&gt;

&lt;P&gt;Anthony&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2013 10:36:56 GMT</pubDate>
    <dc:creator>anthonycopus</dc:creator>
    <dc:date>2013-09-09T10:36:56Z</dc:date>
    <item>
      <title>json in splunk is ignoring the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-in-splunk-is-ignoring-the-timestamp/m-p/57574#M11248</link>
      <description>&lt;P&gt;Hi I currently have the following json in splunk:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{"first_name": "john", "last_name": "black", "timestamp": "2013-09-09 08:00:00", "age": "26", "activity": "start"}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The issue is that splunk should read the timestamp and use that for the time the event is logged. However, it simply is taking the time the event was indexed into the system instead. There is no problem with the other fields, they are parsed fine by splunk.&lt;/P&gt;

&lt;P&gt;How should I make splunk recognise the timestamp in this json? Is it possible for it to be done automatically if the format the timestamp is written in it changed?&lt;/P&gt;

&lt;P&gt;Anthony&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 10:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-in-splunk-is-ignoring-the-timestamp/m-p/57574#M11248</guid>
      <dc:creator>anthonycopus</dc:creator>
      <dc:date>2013-09-09T10:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: json in splunk is ignoring the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/json-in-splunk-is-ignoring-the-timestamp/m-p/57575#M11249</link>
      <description>&lt;P&gt;See &lt;A href="http://answers.splunk.com/answers/104500/transforming-timestamps"&gt;http://answers.splunk.com/answers/104500/transforming-timestamps&lt;/A&gt; &lt;BR /&gt;
Might help&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2013 08:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/json-in-splunk-is-ignoring-the-timestamp/m-p/57575#M11249</guid>
      <dc:creator>amanteja</dc:creator>
      <dc:date>2013-10-06T08:14:25Z</dc:date>
    </item>
  </channel>
</rss>

