<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk timeformat issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693364#M115262</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I am using the standalone machine ( act as search head and indexer both ). So its good to add this attribute in props ?&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2024 11:06:14 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-07-15T11:06:14Z</dc:date>
    <item>
      <title>Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693311#M115239</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a below event and I want to parse. But the event is not parsing with time format in Splunk. Please help me to get it fix .&lt;/P&gt;&lt;P&gt;TIME_FORMAT :&lt;/P&gt;&lt;P&gt;%dT%H:%M:%S.%3QZ&lt;/P&gt;&lt;P&gt;TIME_PREFIX :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;\&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext\:EventTime\&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have used the above setting but nothings works. StillI can see isse with indexed and event time. Please help me to get it fix.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1721015920771.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31747iC374D7CE093360C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1721015920771.png" alt="uagraw01_0-1721015920771.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the raw events:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:EquipmentEvent&lt;/SPAN&gt; &lt;SPAN class=""&gt;xmlns:eqtext=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="http://vanderlande.com/FM/EqtEvent/EqtEventExtTypes/V1/1/5" target="_blank" rel="noopener"&gt;http:///FM/EqtEvent/EqtEventExtTypes/V1/1/5&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;xmlns:sbt=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="http://vanderlande.com/FM/Common/Services/ServicesBaseTypes/V1/8/4" target="_blank" rel="noopener"&gt;http://FM/Common/Services/ServicesBaseTypes/V1/8/4&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;xmlns:eqtexo=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="http://vanderlande.com/FM/EqtEvent/EqtEventExtOut/V1/1/5" target="_blank" rel="noopener"&gt;http://FM/EqtEvent/EqtEventExtOut/V1/1/5&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:ID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:Location&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:PhysicalLocation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;AreaID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;7053&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/AreaID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ZoneID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;33&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/ZoneID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;EquipmentID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;25&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/EquipmentID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ElementID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/ElementID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:PhysicalLocation&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:Location&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:Description&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Welder&lt;/SPAN&gt; &lt;SPAN class=""&gt;cold&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:Description&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:MIS_Address&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;6.2&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:MIS_Address&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:ID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:Detail&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;State&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;CAME_IN&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/State&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:EventTime&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;2024-07-13T16:21:31.287Z&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:EventTime&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:MsgNr&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;7751154552301783480&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:MsgNr&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Severity&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/Severity&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;eqtext:OperatorID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;WALVAU-SCADA-1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:OperatorID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ErrorType&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TECHNICAL&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/ErrorType&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:Detail&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtext:EquipmentEvent&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/eqtexo:EquipmentEventReport&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 09:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693311#M115239</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T09:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693315#M115240</link>
      <description>&lt;P&gt;Should be "&lt;SPAN&gt;%FT%H:%M:%S.%3Q%Z". &amp;nbsp;You can always test your time format with an emulation, like&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="eqtext:EventTime
2024-07-13T16:21:31.287Z"
| eval _time = strptime('eqtext:EventTime', "%FT%H:%M:%S.%3Q%Z")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693315#M115240</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-15T04:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693317#M115241</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults | eval logs="2024-07-13T16:21:31.287Z" 
| eval time=strptime(logs,"%Y-%m-%dT%H:%M:%S.%Q")
| eval date = strftime(time,"%Y-%m-%d %H:%M:%S") | table logs time date&lt;/LI-CODE&gt;&lt;P&gt;... pls check "%Y-%m-%dT%H:%M:%S.%Q"&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="timestamp-july15.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31748iFE5273C6E50EE003/image-size/large?v=v2&amp;amp;px=999" role="button" title="timestamp-july15.jpg" alt="timestamp-july15.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:32:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693317#M115241</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-15T04:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693319#M115242</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp; When I ingested to Splunk both the times varies ( index and event time). Please see below screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1721018147234.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31749iE8A620C5454357BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1721018147234.png" alt="uagraw01_0-1721018147234.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693319#M115242</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T04:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693320#M115243</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;pls show us your props.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(if you dont know where to find the props....&lt;/P&gt;&lt;P&gt;are you using HF or not... if u use HF, then props.conf should be there&lt;/P&gt;&lt;P&gt;if you dont use HF, then, you should have props.conf for this should be in indexer)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:48:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693320#M115243</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-15T04:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693321#M115244</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Scada_walmart_alarm]&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;KV_MODE = xml&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;CHARSET = UTF-8&lt;BR /&gt;LINE_BREAKER = &amp;lt;\/eqtext\:EquipmentEvent&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 24&lt;BR /&gt;TIME_FORMAT = %FT%H:%M:%S.%3Q%Z&lt;BR /&gt;#TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N%Z&lt;BR /&gt;TIME_PREFIX = \&amp;lt;eqtext\:EventTime\&amp;gt;&lt;BR /&gt;SEDCMD-first = s/^.*&amp;lt;eqtext:EquipmentEvent/&amp;lt;eqtext:EquipmentEvent/g&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693321#M115244</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T04:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693324#M115245</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;.. for the timeformat.. did you apply both mine and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;'s timeformat's?..&lt;/P&gt;&lt;P&gt;(after updating the props.conf, you must restart the splunk services.. then only the changes will be inserted to Splunk)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:57:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693324#M115245</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-15T04:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693325#M115246</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp; I have updated this "&lt;SPAN&gt;TIME_FORMAT = %FT%H:%M:%S.%3Q%Z" other is in #&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have already restarted the Splunkd services.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 04:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693325#M115246</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T04:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693326#M115247</link>
      <description>&lt;P&gt;1) Pls give us the search query you are using..&amp;nbsp;&lt;/P&gt;&lt;P&gt;what you see on the results is your splunk user profile's timezone setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) on your Splunk user profile, pls make sure you have the right timezone settings (click on your username---- &amp;gt; Account settings---- &amp;gt; Time Zone)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 05:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693326#M115247</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-15T05:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693328#M115248</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;If you see the below attached screenshot. The first three events is matching but the last one event is always creating an issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;FYI : I am using default timezone setting.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1721021072617.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31750i7152F9031820CD37/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1721021072617.png" alt="uagraw01_0-1721021072617.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 05:25:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693328#M115248</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T05:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693329#M115249</link>
      <description>&lt;P&gt;if 3 results got good timestamp meaning, props.conf is working fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;lets troubleshoot the 4th one..&amp;nbsp;&lt;/P&gt;&lt;P&gt;pls copy paste your search query..&amp;nbsp; (remove the hostnames, confidential info etc.. )&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 05:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693329#M115249</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-07-15T05:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693331#M115250</link>
      <description>&lt;P&gt;1. For "ASAP" you pay your friendly consultant or PS. This is a community-driven forum - people help others in their own spare time. Saying "help me ASAP" can be perceived as rude.&lt;/P&gt;&lt;P&gt;2. How do you ingest your data? UF-&amp;gt;indexer? HF-&amp;gt;indexer? UF-&amp;gt;HF-&amp;gt;indexer? What input do the events come in by. Where do you have the props.conf for the sourcetype?&lt;/P&gt;&lt;P&gt;3. You have the timestamp relatively late in the event and - as you've shown - your MAX_TIMESTAMP_LOOKAHEAD is set to only 24.&lt;/P&gt;&lt;P&gt;4. When posting config excerpts or data samples please use code block or preformatted style. It greatly helps readability.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:09:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693331#M115250</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-15T06:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693335#M115252</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;I have added these&amp;nbsp; three corrected settings in props.conf.&amp;nbsp;I am waiting for the real event to come in, if this works then the job will be done.&lt;BR /&gt;&lt;BR /&gt;LINE_BREAKER = &amp;lt;\/eqtext:EquipmentEvent&amp;gt;()&lt;BR /&gt;TIME_PREFIX = ((?&amp;lt;!ReceiverFmInstanceName&amp;gt;))&amp;lt;eqtext:EventTime&amp;gt;&lt;BR /&gt;TZ = America/Glace_Bay&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693335#M115252</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T06:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693339#M115253</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Please don't take my words otherwise. I didn't mean to say that. Btw way thanks for correcting me. I will take care with my words from the next time.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:20:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693339#M115253</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T06:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693341#M115254</link>
      <description>&lt;P&gt;Thought as much, it's just worth noting that things can be perceived differently than what we wanted to say &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now, check the technical part of my response &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Most probably, you need to increase the lookahead because you have no timestamp in first 24 chars of your event. The architectural issue might also mean that when you fix that you'll be doing the right thing but in wrong place.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693341#M115254</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-15T06:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693344#M115256</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;According to your suggestion my settings will be as below&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 520&lt;BR /&gt;&amp;nbsp;( timestamps comes after 520 character of events)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693344#M115256</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T06:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693346#M115257</link>
      <description>&lt;P&gt;You might want to set it to a bit higher value. The timestamp is relatively late in the event and the part before the timestamp contains dynamic data which can be of varying length so you have to account for that.&lt;/P&gt;&lt;P&gt;Bonus question - you're not using INDEXED_EXTRACTIONS, are you?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693346#M115257</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-15T06:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693349#M115258</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;No, I am not using&lt;STRONG&gt;&amp;nbsp;INDEXED_EXTRACTIONS.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;I am using KV_MODE=xml in my setting ( props). Is there any other significance of&amp;nbsp;&lt;STRONG&gt;INDEXED_EXTRACTIONS ?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 07:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693349#M115258</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-15T07:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693355#M115259</link>
      <description>&lt;P&gt;The first three may be working because Splunk might not be finding the timestamp you are searching for within 520 characters, so it is finding the sbt:MessageTimeStamp, which happens to be the same as the EventTime in these events.&lt;/P&gt;&lt;P&gt;sbt:MessageTimeStamp does not exist in the failing event so Splunk is using the ingest time in the fourth event.&lt;/P&gt;&lt;P&gt;The fourth event is a different format to the the other three events "eqtext:EquipmentEvent" instead of "eqtexo:EquipmentEventReport" so should ideally be in a different sourcetype (at least the source file names are different so it should be relatively easy to split them off).&lt;/P&gt;&lt;P&gt;The timestamp in the fourth event is at least around 627 characters in so your lookahead should at least cover that (and as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said, it looks like you are dealing with variable length data, so 627 may not be enough).&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 08:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693355#M115259</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-15T08:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timeformat issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693363#M115261</link>
      <description>&lt;P&gt;Yes, INDEXED_EXTRACTIONS can alter the procesing path of your event. Without it the event is parsed on the first "heavy" component the event goes through - typically either the intermediate HF or the destination indexer. When you enable indexed extractions on a UF, the data is parsed directly on the originating UF and is not touched after that (apart from possible ingest actions).&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 10:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-timeformat-issue/m-p/693363#M115261</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-15T10:35:06Z</dc:date>
    </item>
  </channel>
</rss>

