<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timestamp fixing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/704006#M116441</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Thanks for your wonderful suggestion in the shared doc link.&amp;nbsp; However, timestamp specification setting is only available in "&lt;STRONG&gt;Batch type"&lt;/STRONG&gt; not available in &lt;STRONG&gt;"Rising Column Type". &lt;/STRONG&gt;Is there any other suggestion or idea to apply this with rising column type also to avoid duplication ingestion of events?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1731168461897.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33431i776191B986B73D55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1731168461897.png" alt="uagraw01_0-1731168461897.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 09 Nov 2024 16:10:48 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-11-09T16:10:48Z</dc:date>
    <item>
      <title>Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703874#M116426</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;BR /&gt;&lt;BR /&gt;I want to extract the _time and match it to the events fields' timestamp while ingesting to Splunk. However, even after applying the props.conf attributes setting, the results still do not match after ingestion. Please advise me on the proper settings and assist me in fixing this one.&lt;/P&gt;&lt;P&gt;Raw events:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2024-11-07&lt;/SPAN&gt; &lt;SPAN class=""&gt;18:45:00.035&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;ID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;51706&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;IDEVENT=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;313032807&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;EVENTTS=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2024-11-07&lt;/SPAN&gt; &lt;SPAN class=""&gt;18:29:43.175&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;INSERTTS=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2024-11-07&lt;/SPAN&gt; &lt;SPAN class=""&gt;18:42:05.819&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;SOURCE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Shuttle.DiagnosticErrorInfoLogList.28722.csv&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;LOCATIONOFFSET=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;LOGTIME=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2024-11-07&lt;/SPAN&gt; &lt;SPAN class=""&gt;18:29:43.175&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;BLOCK=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;SECTION=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;A9.18&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;SIDE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;LOCATIONREF=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;10918&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;ALARMID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;20201&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;RECOVERABLE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;False&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;SHUTTLEID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Shuttle_069&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;ALARM=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;20201&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;LOCATIONDIR=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Front"&lt;BR /&gt;&lt;BR /&gt;Existing props setting:&lt;BR /&gt;&lt;BR /&gt;CHARSET = UTF-8&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;LINE_BREAKER = [0-9]\-[0-9]+\-[0-9]+\s[0-9]+:[0-9]+:[0-9]+.\d+&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;category = Custom&lt;BR /&gt;TIME_PREFIX = EVENTTS="&lt;BR /&gt;TIME_FORMAT = %Y-%m-%d %H:%M:%S.%N&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 30&lt;BR /&gt;TZ = UTC&lt;BR /&gt;&lt;BR /&gt;In the below screeshot still we can see _time is not properly extracted with the matching timestamp of the field name &lt;STRONG&gt;"EVENTTS".&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1731037343060.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33415i7ADA1A23DD87DC4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1731037343060.png" alt="uagraw01_0-1731037343060.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 03:50:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703874#M116426</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-08T03:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703876#M116427</link>
      <description>&lt;P&gt;The screenshot shows the timestamp as "&lt;SPAN class=""&gt;2024-11-07&lt;/SPAN&gt; &lt;SPAN class=""&gt;18:45:00.035", the event time as "11/7/24&amp;nbsp;6:45:00.035 PM". &amp;nbsp; What exactly do not match?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 04:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703876#M116427</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-11-08T04:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703880#M116428</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;EVENTTS=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2024-11-07&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;18:29:43.175&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I want to match _time with above timestamps.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 05:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703880#M116428</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-08T05:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703882#M116429</link>
      <description>&lt;P&gt;I see. &amp;nbsp;TIME_PREFIX is a regex. &amp;nbsp;So, you need to escape quotation marks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX = EVENTTS=\"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 06:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703882#M116429</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-11-08T06:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703884#M116430</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp; You mean like as below ?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;TIME_PREFIX= EVENTTS=\&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 06:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703884#M116430</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-08T06:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703886#M116431</link>
      <description>&lt;P&gt;Yes. &amp;nbsp;Sorry I erased = when editing text&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 06:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703886#M116431</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-11-08T06:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703912#M116432</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;Hi, I have made the suggested changes but still _time is not matching with the raw event field (EVENTTS) timestamp. Please suggest me to do the needful.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1731060967762.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33425iC2105311B08166F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1731060967762.png" alt="uagraw01_0-1731060967762.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 10:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703912#M116432</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-08T10:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703967#M116433</link>
      <description>&lt;P&gt;Using your illustrated event as input, this is my test output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2024-11-08 at 7.18.07 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33429i770296D60DECA9F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2024-11-08 at 7.18.07 PM.png" alt="Screen Shot 2024-11-08 at 7.18.07 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Displayed event time is&amp;nbsp;&lt;SPAN&gt;11/7/24&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;6:29:43.175 PM, which matches EVENTTS value of&amp;nbsp;2024-11-07 18:29:43.175 and differs from the log's timestamp of&amp;nbsp;2024-11-07 18:45:00.035.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is my sourcetype entry:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[test-eventts]
DATETIME_CONFIG = 
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
TIME_PREFIX = EVENTTS=\"
category = Custom
description = https://community.splunk.com/t5/Splunk-Search/Timestamp-fixing/m-p/703912#M238560
pulldown_type = 1&lt;/LI-CODE&gt;&lt;P&gt;The sourcetype is created from default except TIME_PREFIX. (Pro tip: Splunk's default timestamp detection is very versatile and often not worth overriding.)&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 03:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703967#M116433</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-11-09T03:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703968#M116434</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;You have not used both below attributes. Can I also skip these two? Not using it will not have any impact on the consistency of data parsing, right?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;TIME_FORMAT&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;MAX_TIME_LOOKAHEAHD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and acknowledging your valuable time.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 04:02:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703968#M116434</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-09T04:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703995#M116435</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;You should normally &lt;EM&gt;not&lt;/EM&gt; need to escape quotes. It's not a rex command in SPL.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;How are you ingesting your data and where do you put those props? (On which server?)&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 07:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703995#M116435</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-09T07:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703996#M116436</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; I am putting props setting under&lt;/P&gt;&lt;P&gt;/app/local&lt;/P&gt;&lt;P&gt;Note : Data is ingesting to Splunk from DB connect app. So I have applied all the props settings under /db_connect_ap/local&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 07:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703996#M116436</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-09T07:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703997#M116437</link>
      <description>&lt;P&gt;Ha!&lt;/P&gt;&lt;P&gt;So it's a modular input. With modular inputs time processing works a bit differently. See &lt;A href="https://dev.splunk.com/enterprise/docs/developapps/manageknowledge/custominputs/modinputsscript" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/developapps/manageknowledge/custominputs/modinputsscript&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You need to configure your database input properly&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/DBX/3.18.1/DeployDBX/Createandmanagedatabaseinputs" target="_blank"&gt;https://docs.splunk.com/Documentation/DBX/3.18.1/DeployDBX/Createandmanagedatabaseinputs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;or - if you can't find suitable combination of parameters - you need to use INGEST_EVAL to modify the _time field after initial parsing stages during ingestion.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 09:04:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/703997#M116437</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-09T09:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/704006#M116441</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Thanks for your wonderful suggestion in the shared doc link.&amp;nbsp; However, timestamp specification setting is only available in "&lt;STRONG&gt;Batch type"&lt;/STRONG&gt; not available in &lt;STRONG&gt;"Rising Column Type". &lt;/STRONG&gt;Is there any other suggestion or idea to apply this with rising column type also to avoid duplication ingestion of events?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1731168461897.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33431i776191B986B73D55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1731168461897.png" alt="uagraw01_0-1731168461897.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 16:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/704006#M116441</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-09T16:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp fixing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/704008#M116443</link>
      <description>&lt;P&gt;As I said, if you can't configure your input that it assigns _time automatically, you're limited to using INGEST_EVAL to find the timestamp within your event and then strptime it.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 16:28:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-fixing/m-p/704008#M116443</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-09T16:28:23Z</dc:date>
    </item>
  </channel>
</rss>

