<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Not Recognizing Timestamps – What Settings Should I Use? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710424#M117328</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’m having trouble getting Splunk to recognize timestamps correctly, and I hope someone can help me out. I’m importing an &lt;/SPAN&gt;&lt;SPAN&gt;access log file&lt;/SPAN&gt;&lt;SPAN&gt;, where the timestamps are formatted like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;01&lt;/SPAN&gt;&lt;SPAN&gt;/Jan/&lt;/SPAN&gt;&lt;SPAN&gt;2017&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;16&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;51&lt;/SPAN&gt;&lt;SPAN&gt; -0800]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;here also a live output:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="81341BD6-AE01-4FF1-99EA-6C755D6680AD.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34337i1524C57B3A9A9F06/image-size/large?v=v2&amp;amp;px=999" role="button" title="81341BD6-AE01-4FF1-99EA-6C755D6680AD.png" alt="81341BD6-AE01-4FF1-99EA-6C755D6680AD.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, Splunk is not recognizing these timestamps and instead assigns the &lt;/SPAN&gt;&lt;SPAN&gt;indexing time&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have tried adjusting the settings in the &lt;/SPAN&gt;&lt;SPAN&gt;sourcetype configuration&lt;/SPAN&gt;&lt;SPAN&gt; (see screenshot) and have set the following values:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Timestamp format:&lt;/SPAN&gt; &lt;SPAN&gt;%d/%b/%Y:%H:%M:%S %z&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Timestamp prefix:&lt;/SPAN&gt; &lt;SPAN&gt;\[&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Lookahead:&lt;/SPAN&gt; &lt;SPAN&gt;32&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately, the timestamps are still not recognized correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;Do I need to modify &lt;/SPAN&gt;&lt;SPAN&gt;props.conf&lt;/SPAN&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;SPAN&gt;inputs.conf&lt;/SPAN&gt;&lt;SPAN&gt; as well?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;Is my timestamp format correct, or should it be defined differently?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;Could there be another issue in my extraction settings?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log file looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_1085.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34339iDD4661113378B284/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_1085.jpeg" alt="IMG_1085.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Should I maybe change the log file with some scripting in order to change the format?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would really appreciate any guidance! Thank you in advance. &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Feb 2025 12:00:04 GMT</pubDate>
    <dc:creator>splunk_user_99</dc:creator>
    <dc:date>2025-02-02T12:00:04Z</dc:date>
    <item>
      <title>Splunk Not Recognizing Timestamps – What Settings Should I Use?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710424#M117328</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’m having trouble getting Splunk to recognize timestamps correctly, and I hope someone can help me out. I’m importing an &lt;/SPAN&gt;&lt;SPAN&gt;access log file&lt;/SPAN&gt;&lt;SPAN&gt;, where the timestamps are formatted like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;01&lt;/SPAN&gt;&lt;SPAN&gt;/Jan/&lt;/SPAN&gt;&lt;SPAN&gt;2017&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;16&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;51&lt;/SPAN&gt;&lt;SPAN&gt; -0800]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;here also a live output:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="81341BD6-AE01-4FF1-99EA-6C755D6680AD.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34337i1524C57B3A9A9F06/image-size/large?v=v2&amp;amp;px=999" role="button" title="81341BD6-AE01-4FF1-99EA-6C755D6680AD.png" alt="81341BD6-AE01-4FF1-99EA-6C755D6680AD.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, Splunk is not recognizing these timestamps and instead assigns the &lt;/SPAN&gt;&lt;SPAN&gt;indexing time&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have tried adjusting the settings in the &lt;/SPAN&gt;&lt;SPAN&gt;sourcetype configuration&lt;/SPAN&gt;&lt;SPAN&gt; (see screenshot) and have set the following values:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Timestamp format:&lt;/SPAN&gt; &lt;SPAN&gt;%d/%b/%Y:%H:%M:%S %z&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Timestamp prefix:&lt;/SPAN&gt; &lt;SPAN&gt;\[&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;SPAN&gt;Lookahead:&lt;/SPAN&gt; &lt;SPAN&gt;32&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately, the timestamps are still not recognized correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;Do I need to modify &lt;/SPAN&gt;&lt;SPAN&gt;props.conf&lt;/SPAN&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;SPAN&gt;inputs.conf&lt;/SPAN&gt;&lt;SPAN&gt; as well?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;Is my timestamp format correct, or should it be defined differently?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;Could there be another issue in my extraction settings?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log file looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_1085.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34339iDD4661113378B284/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_1085.jpeg" alt="IMG_1085.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Should I maybe change the log file with some scripting in order to change the format?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would really appreciate any guidance! Thank you in advance. &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2025 12:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710424#M117328</guid>
      <dc:creator>splunk_user_99</dc:creator>
      <dc:date>2025-02-02T12:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Recognizing Timestamps – What Settings Should I Use?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710425#M117329</link>
      <description>&lt;P&gt;It looks like your time extraction settings are corrrect, however you need to add&amp;nbsp;MAX_DAYS_AGO to be a higher value (eg 3000) for Splunk to accept that 2017 timestamp as the default is 2000 and therefore Splunk is not accepting the date.&lt;/P&gt;&lt;P&gt;Let me know if adding&amp;nbsp;MAX_DAYS_AGO=3000 to your extraction config works!&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2025 12:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710425#M117329</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-02-02T12:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Recognizing Timestamps – What Settings Should I Use?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710436#M117332</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hey Will,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I just wanted to say &lt;/SPAN&gt;&lt;SPAN&gt;a huge THANK YOU&lt;/SPAN&gt;&lt;SPAN&gt; for your help! &lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your suggestion to increase &lt;/SPAN&gt;&lt;SPAN&gt;MAX_DAYS_AGO&lt;/SPAN&gt;&lt;SPAN&gt; to 3000 &lt;/SPAN&gt;&lt;SPAN&gt;completely solved my issue&lt;/SPAN&gt;&lt;SPAN&gt;, and Splunk now correctly recognizes my timestamps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Honestly, I had been struggling with this for quite some time, and your solution &lt;/SPAN&gt;&lt;SPAN&gt;saved me a lot of time and frustration&lt;/SPAN&gt;&lt;SPAN&gt;. I really appreciate the effort you put into answering my question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again, and have a great day! &lt;span class="lia-unicode-emoji" title=":rocket:"&gt;🚀&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Emil&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2025 18:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Recognizing-Timestamps-What-Settings-Should-I-Use/m-p/710436#M117332</guid>
      <dc:creator>splunk_user_99</dc:creator>
      <dc:date>2025-02-02T18:54:55Z</dc:date>
    </item>
  </channel>
</rss>

