<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timestamp extractor issue on UF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752044#M119425</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I copied props.conf to indexers and it works properly :-).&lt;/P&gt;&lt;P&gt;Thank you and have a nice day!&lt;/P&gt;</description>
    <pubDate>Fri, 22 Aug 2025 10:02:50 GMT</pubDate>
    <dc:creator>LIS</dc:creator>
    <dc:date>2025-08-22T10:02:50Z</dc:date>
    <item>
      <title>Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751974#M119404</link>
      <description>&lt;P&gt;I have two time stamps in each record&amp;nbsp;&lt;SPAN&gt;2025-08-20 17:37:00.317 and&amp;nbsp;SEN_20250820153640.1703351.txt.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And want to use first one, but timestamp extractor chooses second from file name, neglecting my config.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Example of record:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2025-08-20 17:37:00.317 INF transferred file bytes=7642 file=/map/sen-tig/SEN_20250820153640.1703351.txt pid=4170 speed_mbps=2.1 time_ms=29.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;inputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[monitor:///apps/sftp_sender/var/log/sftp*.log]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = messaging&lt;BR /&gt;sourcetype = messaging:ms:log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[messaging:ms:log]&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;TIME_PREFIX = ^&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 23&lt;BR /&gt;TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N&lt;BR /&gt;TZ = Europe/Brussels&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also tried to use&amp;nbsp;DATETIME_CONFIG = NONE (and CURRENT) , but it doesnt work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I still see in Splunk _time = "second timestamp from record".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[messaging:ms:log]&lt;BR /&gt;TZ = Europe/Brussels&lt;BR /&gt;DATETIME_CONFIG = NONE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 11:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751974#M119404</guid>
      <dc:creator>LIS</dc:creator>
      <dc:date>2025-08-21T11:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751984#M119406</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240613"&gt;@LIS&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;where did you locate the props.conf file?&lt;/P&gt;&lt;P&gt;you must put it on the UF and on the first full Splunk instance.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 15:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751984#M119406</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-08-21T15:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751988#M119407</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590774" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Timestamp recognition happens usually on the first "heavy" component the event goes through. So your time-related settings should be put there (usually on indexer(s) or a Heavy Forwarder if you have one between your UF and indexer(s)). There is one caveat though - if you use indexed extractions - they happen on the initial ingesting component even if it's a UF. But that's a rare use case.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 17:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751988#M119407</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-21T17:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751995#M119410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your responses, but it is not clear for me, because in our system we have lots of configs/dataflows were we have props.conf with time related parameters (TIMESTAMP_FIELDS, TIME_PREFIX, MAX_TIMESTAMP_LOOKAHEAD, TIME_FORMAT, TZ .... ) only on UF.&amp;nbsp; Our forwarders connected to indexers directly, we dont have any props.conf on indexers and it work properly).&lt;/P&gt;&lt;P&gt;maybe it only works with&amp;nbsp;INDEXED_EXTRACTIONS ?&lt;/P&gt;&lt;P&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;FIELD_DELIMITER = ,&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Structured&lt;BR /&gt;disabled = false&lt;BR /&gt;TIMESTAMP_FIELDS = date&lt;BR /&gt;TIME_FORMAT = %Y-%m-%d %H:%M:%S&lt;BR /&gt;TZ = UTC&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 18:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/751995#M119410</guid>
      <dc:creator>LIS</dc:creator>
      <dc:date>2025-08-21T18:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752002#M119412</link>
      <description>&lt;P&gt;If you don't have the proper config on the parsing component Splunk guesses. Sometimes does it relatively well but it's not good performancewise.&lt;/P&gt;&lt;P&gt;Also TIMESTAMP_FIELDS makes sense only with indexed extractions.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 20:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752002#M119412</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-21T20:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752005#M119414</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240613"&gt;@LIS&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;some pasring activities are done on the Forwarders and some others are done on the first full Splunk instance that data are passing through, in your case Indexers.&lt;/P&gt;&lt;P&gt;Put the props.conf on the UFs and on Indexersa, and, if you have, on Search Heads.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 21:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752005#M119414</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-08-21T21:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752032#M119423</link>
      <description>&lt;P&gt;Thank you for more details).&lt;BR /&gt;&lt;BR /&gt;Unfortunately, it is not really clear in Splunk docs where we can use certain parameter (only UF, HF, Indexer or on any of them). how to get it?&lt;/P&gt;&lt;P&gt;So, I have to copy my props.conf on indexers as well, or move it from UF to indexers?&lt;/P&gt;&lt;P&gt;Thank you in advance:-)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 07:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752032#M119423</guid>
      <dc:creator>LIS</dc:creator>
      <dc:date>2025-08-22T07:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752033#M119424</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240613"&gt;@LIS&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I usually put it both on UFs and Indexers, and Search Heads.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 08:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752033#M119424</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-08-22T08:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752044#M119425</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I copied props.conf to indexers and it works properly :-).&lt;/P&gt;&lt;P&gt;Thank you and have a nice day!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 10:02:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752044#M119425</guid>
      <dc:creator>LIS</dc:creator>
      <dc:date>2025-08-22T10:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp extractor issue on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752045#M119426</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240613"&gt;@LIS&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 10:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-extractor-issue-on-UF/m-p/752045#M119426</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-08-22T10:07:13Z</dc:date>
    </item>
  </channel>
</rss>

