<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time config incorrect in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-config-incorrect/m-p/710123#M117295</link>
    <description>&lt;P&gt;I updated it to a 4 digit year to match my logs.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%d %b %Y %H:%M:%S, %Z&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2025 11:28:47 GMT</pubDate>
    <dc:creator>_joe</dc:creator>
    <dc:date>2025-01-29T11:28:47Z</dc:date>
    <item>
      <title>Time config incorrect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-config-incorrect/m-p/710122#M117294</link>
      <description>&lt;P&gt;This isn't so much a question as a comment. I found that time config to be incorrect.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My logs start like this:&lt;BR /&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;29&lt;/SPAN&gt; &lt;SPAN class=""&gt;Jan&lt;/SPAN&gt; &lt;SPAN class=""&gt;2025&lt;/SPAN&gt; &lt;SPAN class=""&gt;03:16:30&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;PST&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The default timestring is expecting a 2 digit year.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%d %b %y %H:%M:%S, %Z&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Prior to the update, Splunk was stil able to figure out the time but issed the timezone parameter. In other words, if your heavy forwarder has the same timezone as your zScaler logs you would probably be fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 11:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-config-incorrect/m-p/710122#M117294</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2025-01-29T11:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Time config incorrect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-config-incorrect/m-p/710123#M117295</link>
      <description>&lt;P&gt;I updated it to a 4 digit year to match my logs.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%d %b %Y %H:%M:%S, %Z&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 11:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-config-incorrect/m-p/710123#M117295</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2025-01-29T11:28:47Z</dc:date>
    </item>
  </channel>
</rss>

