<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcetype for JSON data fails to extract the timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749531#M119080</link>
    <description>&lt;P&gt;Thank you for the suggestion!&lt;/P&gt;&lt;P&gt;I tried "&lt;SPAN&gt;%Y-%m-%dT%H:%M:%S%:z" - same results (seems like timestamp extraction is ignored &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp; ).&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I also validated my time format in PHP and Python strptime("2025-07-09T15:50:20+00:00", "%Y-%m-%dT%H:%M:%S%z") - it seems to work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I do send to /event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I tried sending to /raw I get this (seems like it considers the RAW HTTP request data as "data"):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mmaaxx_0-1752090944427.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39625i416828C5C361C77E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mmaaxx_0-1752090944427.png" alt="mmaaxx_0-1752090944427.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It doesn't seem to be related to parsing.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jul 2025 19:58:17 GMT</pubDate>
    <dc:creator>mmaaxx</dc:creator>
    <dc:date>2025-07-09T19:58:17Z</dc:date>
    <item>
      <title>Sourcetype for JSON data fails to extract the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749524#M119077</link>
      <description>&lt;P&gt;I feed data to Splunk using the HTTP Event Collector, sample event:&lt;/P&gt;&lt;P&gt;{&lt;/P&gt;&lt;P&gt;"event":{&lt;/P&gt;&lt;P&gt;"event_id": "58512040",&lt;/P&gt;&lt;P&gt;"event_name": "Access Granted",&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;"event_local_time_with_offset":"2025-07-09T14:46:28+00:00",&lt;/P&gt;&lt;P&gt;},&lt;/P&gt;&lt;P&gt;"sourcetype": "BBL_splunk_pacs"&lt;/P&gt;&lt;P&gt;}&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set up &lt;SPAN&gt;datasource type BBL_splunk_pacs (see screenshot below)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I search for the events, I get:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I see 2 issues:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;DIV&gt;_time is not parsed correctly from the event_local_time_with_offset.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;Most of the time, randomly (?), we get all event fields duplicated, and sometimes they are not duplicated.&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what I may be doing wrong?&amp;nbsp; Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mmaaxx_1-1752087006302.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39623iD93C57DF1A89BBEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="mmaaxx_1-1752087006302.png" alt="mmaaxx_1-1752087006302.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 18:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749524#M119077</guid>
      <dc:creator>mmaaxx</dc:creator>
      <dc:date>2025-07-09T18:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype for JSON data fails to extract the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749527#M119078</link>
      <description>&lt;P&gt;Here is a screenshot of the source type:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mmaaxx_0-1752087465960.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39624iEB2266F28DEDA92D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mmaaxx_0-1752087465960.png" alt="mmaaxx_0-1752087465960.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 18:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749527#M119078</guid>
      <dc:creator>mmaaxx</dc:creator>
      <dc:date>2025-07-09T18:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype for JSON data fails to extract the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749529#M119079</link>
      <description>&lt;P&gt;Which HEC endpoint are you sending to?&amp;nbsp; The behavior is different depending on the endpoint.&amp;nbsp; The &lt;FONT face="courier new,courier"&gt;/event&lt;/FONT&gt; endpoint will ignore props settings, but the &lt;FONT face="courier new,courier"&gt;/raw&lt;/FONT&gt; endpoint honors them.&lt;/P&gt;&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;TIME_FORMAT&lt;/FONT&gt; value doesn't match the data.&amp;nbsp; Try using &lt;FONT face="courier new,courier"&gt;%Y-%m-%dT%H:%M:%S%:z&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 19:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749529#M119079</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-07-09T19:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype for JSON data fails to extract the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749531#M119080</link>
      <description>&lt;P&gt;Thank you for the suggestion!&lt;/P&gt;&lt;P&gt;I tried "&lt;SPAN&gt;%Y-%m-%dT%H:%M:%S%:z" - same results (seems like timestamp extraction is ignored &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp; ).&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I also validated my time format in PHP and Python strptime("2025-07-09T15:50:20+00:00", "%Y-%m-%dT%H:%M:%S%z") - it seems to work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I do send to /event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I tried sending to /raw I get this (seems like it considers the RAW HTTP request data as "data"):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mmaaxx_0-1752090944427.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39625i416828C5C361C77E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mmaaxx_0-1752090944427.png" alt="mmaaxx_0-1752090944427.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It doesn't seem to be related to parsing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 19:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749531#M119080</guid>
      <dc:creator>mmaaxx</dc:creator>
      <dc:date>2025-07-09T19:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype for JSON data fails to extract the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749532#M119081</link>
      <description>&lt;P&gt;Sending to the &lt;FONT face="courier new,courier"&gt;/event&lt;/FONT&gt; endpoint skips the props settings.&amp;nbsp; Splunk expects the metadata to be included in the HEC packet.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Data/FormateventsforHTTPEventCollector#Event_metadata" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Data/FormateventsforHTTPEventCollector#Event_metadata&lt;/A&gt;&amp;nbsp;for the supported metadata fields.&lt;/P&gt;&lt;P&gt;Consider adding &lt;FONT face="courier new,courier"&gt;auto_extract_timestamp=true&lt;/FONT&gt; to the HEC URL to tell Splunk to do timestamp parsing.&amp;nbsp; See&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/Timestamp-Not-Extracted-from-JSON-Payload-When-Using-HEC-event-Endpoint-Without-auto-extract-timestamp-true" target="_blank" rel="noopener"&gt;https://splunk.my.site.com/customer/s/article/Timestamp-Not-Extracted-from-JSON-Payload-When-Using-HEC-event-Endpoint-Without-auto-extract-timestamp-true&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 20:14:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749532#M119081</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-07-09T20:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype for JSON data fails to extract the timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749533#M119082</link>
      <description>&lt;P class="lia-align-left"&gt;Thank you for clarifying how it works!&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Sending "time" along with the "event" - fixed the timestamp issue, and setting Indexed Extraction to none - fixed the duplicated fields, as all fields are essentially parsed in the application that feeds the data to the /event endpoint.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 20:51:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-for-JSON-data-fails-to-extract-the-timestamp/m-p/749533#M119082</guid>
      <dc:creator>mmaaxx</dc:creator>
      <dc:date>2025-07-09T20:51:22Z</dc:date>
    </item>
  </channel>
</rss>

