<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk parsing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688442#M114649</link>
    <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;I want to ingest below two pattern of events in Splunk and both are in json logs but there timestamp are different. So far I have used below attributes in my props.conf. Please let me know or suggest me if any any other attribute I need to add so my both the pattern of events parse smoothly without any time difference..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[exp_json]&lt;BR /&gt;AUTO_KV_JSON = false&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;TIME_PREFIX = \"time\"\:\"&lt;BR /&gt;category = Custom&lt;BR /&gt;pulldown_type = true&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Pattern 1:&lt;/STRONG&gt;&lt;BR /&gt;{"datacontenttype":"application/json","data":{"identificationStatus":"NO_IDENTIFICATION_ATTEMPTED","location":"urn:topology:segment:1103.20.15-1103.20.19","carrierId":null,"trackingId":"dc268ac7-168a-11ef-b02a-1feae60bb414"},"subject":"CarrierPositionUpdate","messages":[],"specversion":"1.0","classofpayload":"com.vanderlande.conveyor.boundary.event.business.outbound.CarrierPositionUpdate","id":"8252fb03-2eb2-4619-a59b-24e3280f9bda","source":"conveyor",&lt;STRONG&gt;"time":"2024-05-20T09:29:53.361800Z"&lt;/STRONG&gt;,"type":"CarrierPositionUpdate"}&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pattern 2:&lt;/STRONG&gt;&lt;BR /&gt;{"data":{"physicalId":"60040160041570014272","carrierTypeId":"18","carrierId":"60040160041570014272","prioritizedDestinations":[{"name":"urn:topology:location:Pallet Loop (DEP):OBD/Returnflow:Exit01","priority":1},{"name":"urn:topology:location:Pallet Loop (DEP):OBD/Returnflow:Exit02","priority":1}],"transportOrderId":"TO_00001399"},"topic":"transport-order-commands-conveyor","specversion":"1.0",&lt;STRONG&gt;"time":"2024-05-22T18:02:16.669Z"&lt;/STRONG&gt;,"id":"34A0DF56-B0B2-4A73-9D7B-034A94D49747","type":"AssignTransportOrder"}&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!!&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 10:41:38 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-05-23T10:41:38Z</dc:date>
    <item>
      <title>Splunk parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688442#M114649</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;I want to ingest below two pattern of events in Splunk and both are in json logs but there timestamp are different. So far I have used below attributes in my props.conf. Please let me know or suggest me if any any other attribute I need to add so my both the pattern of events parse smoothly without any time difference..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[exp_json]&lt;BR /&gt;AUTO_KV_JSON = false&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;TIME_PREFIX = \"time\"\:\"&lt;BR /&gt;category = Custom&lt;BR /&gt;pulldown_type = true&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Pattern 1:&lt;/STRONG&gt;&lt;BR /&gt;{"datacontenttype":"application/json","data":{"identificationStatus":"NO_IDENTIFICATION_ATTEMPTED","location":"urn:topology:segment:1103.20.15-1103.20.19","carrierId":null,"trackingId":"dc268ac7-168a-11ef-b02a-1feae60bb414"},"subject":"CarrierPositionUpdate","messages":[],"specversion":"1.0","classofpayload":"com.vanderlande.conveyor.boundary.event.business.outbound.CarrierPositionUpdate","id":"8252fb03-2eb2-4619-a59b-24e3280f9bda","source":"conveyor",&lt;STRONG&gt;"time":"2024-05-20T09:29:53.361800Z"&lt;/STRONG&gt;,"type":"CarrierPositionUpdate"}&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pattern 2:&lt;/STRONG&gt;&lt;BR /&gt;{"data":{"physicalId":"60040160041570014272","carrierTypeId":"18","carrierId":"60040160041570014272","prioritizedDestinations":[{"name":"urn:topology:location:Pallet Loop (DEP):OBD/Returnflow:Exit01","priority":1},{"name":"urn:topology:location:Pallet Loop (DEP):OBD/Returnflow:Exit02","priority":1}],"transportOrderId":"TO_00001399"},"topic":"transport-order-commands-conveyor","specversion":"1.0",&lt;STRONG&gt;"time":"2024-05-22T18:02:16.669Z"&lt;/STRONG&gt;,"id":"34A0DF56-B0B2-4A73-9D7B-034A94D49747","type":"AssignTransportOrder"}&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688442#M114649</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-05-23T10:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688446#M114653</link>
      <description>&lt;P&gt;Ideally, these should be ingested as different sourcetypes so that different parsing can be associated with the different formats.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:51:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688446#M114653</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T10:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688452#M114658</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; I am not using&amp;nbsp; TIME_FORMAT attribute here, then probably it should work ? Please share your thoughts.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 11:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688452#M114658</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-05-23T11:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688455#M114660</link>
      <description>&lt;P&gt;As I said, these look like two different sourcetypes and should be treated as such&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 11:18:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing/m-p/688455#M114660</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T11:18:22Z</dc:date>
    </item>
  </channel>
</rss>

