<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Props not parsing the timestamp for TCP input logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705916#M116752</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a bluecoat proxy log source for which I am using the official splunk addon. However, I noticed that the timestamp is not being parsed for from the logs and instead the index time is being taken.&lt;/P&gt;&lt;P&gt;To remedy this, I added a custom props in ../etc/apps/Splunk_TA_bluecoat-proxysg/local, with the following stanza:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[bluecoat:proxysg:access:syslog]
TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=^&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rest of the configuration is the same as it is in the base app (Splunk_TA_bluecoat-proxysg).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During testing, when I upload logs through&amp;nbsp;&lt;STRONG&gt;Add Data&lt;/STRONG&gt;, the the time stamp is being properly parsed. However when I start using SplunkTCP to ingest the data, the timestamp extraction stops working.&amp;nbsp; Note that in both of the scenarios, the rest of the parsing configurations (field extraction and mapping is working just fine).&lt;/P&gt;&lt;P&gt;Troubleshooting:&lt;/P&gt;&lt;P&gt;1. I tried to check with btool for props .. I can see the custom stanza I added there.&lt;/P&gt;&lt;P&gt;2. Tried putting the props in ../etc/system/local&lt;/P&gt;&lt;P&gt;3. Restarted Splunk multiple times.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any ideas that I can try to get this to work? or where should I look at?&lt;BR /&gt;&lt;BR /&gt;Sample Log:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2024-12-03 07:30:06 9 172.24.126.56 - - - - "None" - policy_denied DENIED "Suspicious" -  200 TCP_ACCELERATED CONNECT - tcp beyondwords-h0e8gjgjaqe0egb7.a03.azurefd.net 443 / - - "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Edg/131.0.0.0" 172.29.184.14 39 294 - - - - - "none" "none" "none" 7 - - 631d69b45739e3b6-00000000df56e125-00000000674eb37e - -&lt;/LI-CODE&gt;&lt;P&gt;Splunk Search (Streaming data):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Utkc137_0-1733313468821.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33698i3D4831682DBFA189/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Utkc137_0-1733313468821.png" alt="Utkc137_0-1733313468821.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Splunk Search (uploaded data):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Utkc137_1-1733313715498.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33699i1B5B4EC161824F37/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Utkc137_1-1733313715498.png" alt="Utkc137_1-1733313715498.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2024 12:04:26 GMT</pubDate>
    <dc:creator>Utkc137</dc:creator>
    <dc:date>2024-12-04T12:04:26Z</dc:date>
    <item>
      <title>Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705916#M116752</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a bluecoat proxy log source for which I am using the official splunk addon. However, I noticed that the timestamp is not being parsed for from the logs and instead the index time is being taken.&lt;/P&gt;&lt;P&gt;To remedy this, I added a custom props in ../etc/apps/Splunk_TA_bluecoat-proxysg/local, with the following stanza:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[bluecoat:proxysg:access:syslog]
TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=^&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rest of the configuration is the same as it is in the base app (Splunk_TA_bluecoat-proxysg).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During testing, when I upload logs through&amp;nbsp;&lt;STRONG&gt;Add Data&lt;/STRONG&gt;, the the time stamp is being properly parsed. However when I start using SplunkTCP to ingest the data, the timestamp extraction stops working.&amp;nbsp; Note that in both of the scenarios, the rest of the parsing configurations (field extraction and mapping is working just fine).&lt;/P&gt;&lt;P&gt;Troubleshooting:&lt;/P&gt;&lt;P&gt;1. I tried to check with btool for props .. I can see the custom stanza I added there.&lt;/P&gt;&lt;P&gt;2. Tried putting the props in ../etc/system/local&lt;/P&gt;&lt;P&gt;3. Restarted Splunk multiple times.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any ideas that I can try to get this to work? or where should I look at?&lt;BR /&gt;&lt;BR /&gt;Sample Log:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2024-12-03 07:30:06 9 172.24.126.56 - - - - "None" - policy_denied DENIED "Suspicious" -  200 TCP_ACCELERATED CONNECT - tcp beyondwords-h0e8gjgjaqe0egb7.a03.azurefd.net 443 / - - "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Edg/131.0.0.0" 172.29.184.14 39 294 - - - - - "none" "none" "none" 7 - - 631d69b45739e3b6-00000000df56e125-00000000674eb37e - -&lt;/LI-CODE&gt;&lt;P&gt;Splunk Search (Streaming data):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Utkc137_0-1733313468821.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33698i3D4831682DBFA189/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Utkc137_0-1733313468821.png" alt="Utkc137_0-1733313468821.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Splunk Search (uploaded data):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Utkc137_1-1733313715498.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33699i1B5B4EC161824F37/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Utkc137_1-1733313715498.png" alt="Utkc137_1-1733313715498.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705916#M116752</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T12:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705917#M116753</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261081"&gt;@Utkc137&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;there's a priority in conf files reading and in that add-on there are some tranformations, so probably the sourcetype you added isn't present when the local file is read and created after using a transformation, see the default sourcetype and try adding your configuration to this sourcetype.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:07:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705917#M116753</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-04T12:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705918#M116754</link>
      <description>&lt;P&gt;Just tested using source in the props stanza name (source is define in inputs.conf) and it's still picking up the index time as the timestamp &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705918#M116754</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T12:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705919#M116755</link>
      <description>&lt;P class="lia-indent-padding-left-30px"&gt;Also, the sourcetype I used originally is also mentioned in the inputs.conf .. and remains the same until the logs are ingested&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:17:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705919#M116755</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T12:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705920#M116756</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261081"&gt;@Utkc137&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you tried with the sourcetype "bluecoat"?&lt;/P&gt;&lt;P&gt;that should be the one you assigned to your input.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705920#M116756</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-04T12:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705921#M116757</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261081"&gt;@Utkc137&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;then, where do you located the add-on?&lt;/P&gt;&lt;P&gt;it should be in the first HF data passed through or (if HFs aren't present) in the Indexers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705921#M116757</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-04T12:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705922#M116758</link>
      <description>&lt;P&gt;Just tested with bluecoat sourcetype .. no luck.&lt;/P&gt;&lt;P&gt;It's a standalone splunk instance (dev env).&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705922#M116758</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T12:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705926#M116760</link>
      <description>&lt;P&gt;Can you share the inputs stanza you have for listening to the TCP stream?&lt;/P&gt;&lt;P&gt;Inside the default application props is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[bluecoat]
rename=bluecoat:proxysg:access:syslog&lt;/LI-CODE&gt;&lt;P&gt;This occurs at search time only per the instructions at:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Propsconf#Sourcetype_configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Propsconf#Sourcetype_configuration&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;rename = &amp;lt;string&amp;gt;
* Renames [&amp;lt;sourcetype&amp;gt;] as &amp;lt;string&amp;gt; at search time
* With renaming, you can search for the [&amp;lt;sourcetype&amp;gt;] with
  sourcetype=&amp;lt;string&amp;gt;
* To search for the original source type without renaming it, use the
  field _sourcetype.
* Data from a renamed sourcetype only uses the search-time
  configuration for the target sourcetype. Field extractions
  (REPORTS/EXTRACT) for this stanza sourcetype are ignored.
* Default: empty string&lt;/PRE&gt;&lt;P&gt;This leaves any _time extraction issues with the source type identified in the inputs.conf stanza.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705926#M116760</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-12-04T13:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705927#M116761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261081"&gt;@Utkc137&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;sorry for the very stupid question: did you restarted your Splunk server after conf update?&lt;/P&gt;&lt;P&gt;Could you share the inputs.conf you are using?&lt;/P&gt;&lt;P&gt;Please thy this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[bluecoat]
TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=^
rename=bluecoat:proxysg:access:syslog

[bluecoat:proxysg:access:syslog]
TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=^
pulldown_type = true
category = Network &amp;amp; Security
description = Data from Blue Coat ProxySG in W3C ELFF format thru syslog
KV_MODE = none
SHOULD_LINEMERGE = false
EVENT_BREAKER_ENABLE=true
MAX_DAYS_AGO = 10951
TRUNCATE  = 64000&lt;/LI-CODE&gt;&lt;P&gt;in local/props.conf&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705927#M116761</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-04T13:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705931#M116763</link>
      <description>&lt;P&gt;Yes, I did restart splunk after each conf change &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here's the inputs.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[splunktcp://9997]
index = mmsproxy
source = tcp.bluecoat
sourcetype = bluecoat:proxysg:access:syslog
disabled = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will check you props too and respond back in a few min&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705931#M116763</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T13:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705932#M116764</link>
      <description>&lt;P&gt;For testing, I tied the props you provided along with these inputs.conf&lt;/P&gt;&lt;P&gt;Test 1:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[splunktcp://9997]
index = mmsproxy
source = tcp.bluecoat
sourcetype = bluecoat:proxysg:access:syslog
disabled = false&lt;/LI-CODE&gt;&lt;P&gt;Test 2:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[splunktcp://9997]
index = mmsproxy
source = tcp.bluecoat
sourcetype = bluecoat
disabled = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Restarted Splunk on both these tests. Still no luck.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:48:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705932#M116764</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T13:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705933#M116765</link>
      <description>&lt;P&gt;Port 9997 is a reserved port for splunk - if this is an external stream from syslog or any other source please select a different port.&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;port=2514&lt;/P&gt;&lt;P&gt;I selected that as 514 is syslog reserved and 1514 I have seen for TCP encrypted syslog so best to just get up and away from that.&amp;nbsp; But by keeping the *514 format it will be easier for others who may inherit your setup to know instinctively that it's a syslog source.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 14:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705933#M116765</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-12-04T14:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705934#M116766</link>
      <description>&lt;P&gt;Switched the inputs to 2154 .. still no luck.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 14:39:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705934#M116766</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T14:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705936#M116767</link>
      <description>&lt;P&gt;This the configuration I have as of now .. I am out of reasons on why this would not work.&amp;nbsp; Am I missing something very basic here?&lt;/P&gt;&lt;P&gt;Inputs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk btool inputs list --debug splunktcp://2514
/opt/splunk/etc/system/local/inputs.conf   [splunktcp://2514]
/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864
/opt/splunk/etc/system/local/inputs.conf   disabled = false
/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup
/opt/splunk/etc/system/local/inputs.conf   index = mmsproxy
/opt/splunk/etc/system/local/inputs.conf   source = tcp.bluecoat
/opt/splunk/etc/system/local/inputs.conf   sourcetype = bluecoat:proxysg:access:syslog&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Props:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk btool props list --debug bluecoat | grep -ie local
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   [bluecoat]
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   TIME_FORMAT = %Y-%m-%d %H:%M:%S
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   TIME_PREFIX = ^
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   rename = bluecoat:proxysg:access:syslog
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   [bluecoat:proxysg:access:syslog]
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   EVENT_BREAKER_ENABLE = true
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   KV_MODE = none
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   MAX_DAYS_AGO = 10951
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   SHOULD_LINEMERGE = false
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   TIME_FORMAT = %Y-%m-%d %H:%M:%S
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   TIME_PREFIX = ^
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   TRUNCATE = 64000
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   category = Network &amp;amp; Security
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   description = Data from Blue Coat ProxySG in W3C ELFF format thru syslog
/opt/splunk/etc/apps/Splunk_TA_bluecoat-proxysg/local/props.conf   pulldown_type = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 14:53:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705936#M116767</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2024-12-04T14:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Props not parsing the timestamp for TCP input logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705945#M116768</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261081"&gt;@Utkc137&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;sorry, but you're receiving logs from BlueCoat using syslog or from another Splunk Forwarder? usually BlueCoat uses syslogs not a Splunk Forwarder.&lt;/P&gt;&lt;P&gt;splunktcp inputs is for log forwarding from another Splunk system not using syslogs!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 16:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-not-parsing-the-timestamp-for-TCP-input-logs/m-p/705945#M116768</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-04T16:34:53Z</dc:date>
    </item>
  </channel>
</rss>

