<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Props.conf - Timestamp extraction failed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-extraction-failed/m-p/699298#M115874</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257739"&gt;@_olivier_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it seems to be a comma separated file, in this case, you must put props.conf also in the UF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 17 Sep 2024 14:55:42 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-09-17T14:55:42Z</dc:date>
    <item>
      <title>Props.conf - Timestamp extraction failed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-extraction-failed/m-p/699263#M115869</link>
      <description>&lt;P&gt;Hi splunkers ! I m facing an issue that is going to make me crazy ! I've got to set the timestamp in the following logs (timestamp field is the 11th field, the first one being the insert time by the proxy himself)&amp;nbsp; : 2024-09-16T13:12:54+02:00 Logging-Client&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"-1","username","1.2.3.4","POST","872","2211","www.facebook.com","/csp/reporting/","OBSERVED","","1726484997","2024-09-16 11:09:57","https","Social Networking","application/x-empty","","Minimal Risk","Remove 'X-Forwarded-For' Header","200","10.97.5.240","","","Firefox","102.0","Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0","firefox.exe","1.2.3.4","443","US","","t","t","t","f","f","computerName","","1.2.3.4","1.2.3.4","8080"&lt;/LI-CODE&gt;&lt;P&gt;So, I'm using a regex to extract fields and set the real timestamp in my props.conf :&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[mySourcetype] SHOULD_LINEMERGE = false EXTRACT-mySourcetype = ^[^,\n]*,"(?P\w+)","(?P[^"]+)","(?P\w+)","(?P[^"]+)[^,\n]*,"(?P[^"]+)[^,\n]*,"(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P(?=\s*)|[^"]+)","(?P[^"]+)","(?P[^"]+)","(?P[^"]+)"$ TIME_PREFIX = (?:[^,]+,){11} TIME_FORMAT = %Y-%m-%d %H:%M:%S&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Then, Ive got different results based on different source:&lt;/P&gt;&lt;P&gt;Upload a file directly in the search head &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Extraction&amp;nbsp; &amp;nbsp; &lt;STRONG&gt;&lt;FONT color="#339966"&gt;Ok &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/FONT&gt; &lt;/STRONG&gt;Timestamp&amp;nbsp; &amp;nbsp; &lt;STRONG&gt;&lt;FONT color="#339966"&gt;OK &lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;File red from an universal forwarder &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Extraction&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;OK &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/FONT&gt; &lt;/STRONG&gt;Timestamp&amp;nbsp;&amp;nbsp;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;Failed &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The is NO heavy forwarder between the UF and the indexers.&lt;/P&gt;&lt;P&gt;The props.conf is deployed only on the SearchHeads. So, Something is tricky here !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone got an idea, I will apreciate ! Cheers.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 09:21:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-extraction-failed/m-p/699263#M115869</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2024-09-17T09:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf - Timestamp extraction failed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-extraction-failed/m-p/699298#M115874</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257739"&gt;@_olivier_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it seems to be a comma separated file, in this case, you must put props.conf also in the UF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 14:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-extraction-failed/m-p/699298#M115874</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-17T14:55:42Z</dc:date>
    </item>
  </channel>
</rss>

