<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk event time and the raw event time difference in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694977#M115450</link>
    <description>&lt;P&gt;Have you read my previous response? Did you check any of the things I mentioned?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2024 13:07:42 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-08-01T13:07:42Z</dc:date>
    <item>
      <title>Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694117#M115344</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;Please help me to fix this time zone issue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1721793712253.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31861i275B56B973F639CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1721793712253.png" alt="uagraw01_0-1721793712253.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 05:19:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694117#M115344</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-24T05:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694118#M115345</link>
      <description>&lt;P&gt;And your current settings are...?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 04:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694118#M115345</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-24T04:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694120#M115346</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Props.conf setting&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;KV_MODE = xml&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;CHARSET = UTF-8&lt;BR /&gt;LINE_BREAKER = &amp;lt;\/eqtext:EquipmentEvent&amp;gt;()&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 650&lt;BR /&gt;TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3QZ&lt;BR /&gt;TIME_PREFIX = ((?&amp;lt;!ReceiverFmInstanceName&amp;gt;))&amp;lt;eqtext:EventTime&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User time preference setting&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1721796309110.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31862i71E43D2E1682F343/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1721796309110.png" alt="uagraw01_0-1721796309110.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 04:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694120#M115346</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-24T04:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694121#M115347</link>
      <description>&lt;P&gt;At first glance it looks relatively ok. Are you using indexed extractions?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 04:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694121#M115347</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-24T04:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694122#M115348</link>
      <description>&lt;P&gt;No, I am not using that attribute in props.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 04:57:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694122#M115348</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-24T04:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694127#M115349</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;When I am using this time preference then there is no difference showing. So its good to setup this setting ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1721797768944.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31864iBEE2633E326EDAFC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1721797768944.png" alt="uagraw01_0-1721797768944.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there anything else you want me to&amp;nbsp; suggest for fix ?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 05:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694127#M115349</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-24T05:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694138#M115352</link>
      <description>&lt;P&gt;Wait a second. You're trying to say that regardless of what timezone you set in your preferences the event is still shown at the same time for the same event? (The time on the left, not the time within the event itself obviously since this one is already ingested, indexed and it won't change). That should be impossible.&lt;/P&gt;&lt;P&gt;BTW, what does your ingestion architecture look like for this source? File-&amp;gt;UF-&amp;gt;indexer? Where do you have your props.conf settings (on which component)?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 07:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694138#M115352</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-24T07:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694167#M115354</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; I am using single standalone machine and the data coming through the nework directory. That network directory produces files and then using inputs.conf I am monitoring into Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 08:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694167#M115354</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-07-24T08:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694198#M115360</link>
      <description>&lt;P&gt;Are you sure your lookahead is big enough? I haven't counted exactly but your event seems close to exceeding that 650 characters mark before reaching the timestamp.&lt;/P&gt;&lt;P&gt;Also - have you verified your TIMESTAMP_PREFIX? That capture group looks strange and you have a very strange lookbehind which seems to not do what you think it should do. Verify it on regex101.com&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 12:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694198#M115360</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-24T12:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694974#M115449</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Sorry for the delayed response. But my concern I am mentioning below in the screenshot. Please help to fix. Is there any setting I need to add in props.conf.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1722516062374.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32006i1DCEEB563865804F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1722516062374.png" alt="uagraw01_0-1722516062374.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 12:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694974#M115449</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-01T12:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694977#M115450</link>
      <description>&lt;P&gt;Have you read my previous response? Did you check any of the things I mentioned?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 13:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694977#M115450</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-01T13:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694979#M115451</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I have increased the max_timestamp from 650 to 750 as well as corrected the TIME_PREFIX setting also but still the issue persist.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 13:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/694979#M115451</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-01T13:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/695042#M115456</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; Actually I got the issue; in my data there is two pattern of events as mentioned below. Therefore, in&amp;nbsp; props.conf I am using TIME_PREFIX =&amp;nbsp;\&amp;lt;\/ReceiverFmInstanceName\&amp;gt;\&amp;lt;eqtext\:EventTime\&amp;gt; &amp;amp;&amp;nbsp;TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3QZ&amp;nbsp; and because the TIME_PREFIX setting&amp;nbsp; as mentioned Splunk is picking only &lt;STRONG&gt;Pattern 1&amp;nbsp;&lt;/STRONG&gt;and skipping &lt;STRONG&gt;Pattern 2 . &lt;/STRONG&gt;So please suggest can I remove TIME_PREFIX setting from the props.conf so Splunk will cover or pick both the events (pattern 1 &amp;amp; pattern 2?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;================================&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Patterrn 1:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;In this pattern &lt;STRONG&gt;Time_Prefix&lt;/STRONG&gt; is looking different&amp;nbsp;&lt;BR /&gt;&amp;lt;/ReceiverFmInstanceName&amp;gt;&amp;lt;eqtext:EventTime&amp;gt;2024-08-01T21:23:37.560Z&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;=================================&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Patterrn 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;In this pattern&amp;nbsp;&lt;STRONG&gt;Time_Prefix&lt;/STRONG&gt; is looking different&amp;nbsp;&lt;BR /&gt;&amp;lt;/State&amp;gt;&amp;lt;eqtext:EventTime&amp;gt;2024-08-01T21:23:37.560Z&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 05:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/695042#M115456</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-02T05:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/695077#M115462</link>
      <description>&lt;P&gt;No. If you remove it, Splunk will be trying to guess and that's performance-intensive.&lt;/P&gt;&lt;P&gt;I don't know your data and don't know whether you don't have more border cases but you can use a regex with alternative branches to match either form)&lt;/P&gt;&lt;PRE&gt;TIME_PREFIX = (&amp;lt;/ReceiverFmInstanceName&amp;gt;&amp;lt;eqtext:EventTime&amp;gt;|&amp;lt;/State&amp;gt;&amp;lt;eqtext:EventTime&amp;gt;)&lt;/PRE&gt;&lt;P&gt;(I'm not sure if some of those characters do not require ecaping so take it with a pinch of salt)&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 11:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/695077#M115462</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-02T11:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event time and the raw event time difference</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/695145#M115465</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Thanks for this suggestion. I will incorporate this change into the props settings.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Aug 2024 03:19:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-event-time-and-the-raw-event-time-difference/m-p/695145#M115465</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-03T03:19:29Z</dc:date>
    </item>
  </channel>
</rss>

