<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cisco encore Events with no Timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752200#M119442</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308735"&gt;@b17gunnr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want Splunk to stop searching for timestamps, just go to your Indexer or Heavy Forwarder (whichever is doing the parsing) and update the props.conf for the relevant sourcetype&lt;/P&gt;&lt;P&gt;Eg:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
DATETIME_CONFIG = NONE
SHOULD_LINEMERGE = false
NO_BINARY_CHECK = true&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Tells Splunk not to attempt timestamp extraction. It will use the index time as the event time&lt;/P&gt;&lt;P&gt;Note: Are you using any specific add-on for this?&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 26 Aug 2025 04:20:46 GMT</pubDate>
    <dc:creator>PrewinThomas</dc:creator>
    <dc:date>2025-08-26T04:20:46Z</dc:date>
    <item>
      <title>Splunk Cisco encore Events with no Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752188#M119441</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;Splunk is cranky with errors stating:&amp;nbsp;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;parse&lt;/SPAN&gt; &lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;first&lt;/SPAN&gt; &lt;SPAN class=""&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/SPAN&gt; (&lt;SPAN class=""&gt;40&lt;/SPAN&gt;) &lt;SPAN class=""&gt;characters&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;event&lt;/SPAN&gt;&lt;/SPAN&gt;. &lt;SPAN class=""&gt;Defaulting&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;previous&lt;/SPAN&gt; &lt;/EM&gt;&lt;SPAN class=""&gt;&lt;EM&gt;event&lt;/EM&gt;. This is related to my Cisco estreamer ingest and there are no timestamps in any of the events.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Is there a way to tell the Indexer that there are no timestamps, that it should not use the lookahead, and configure the index time as the event time for the specific index and sourcetype?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 22:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752188#M119441</guid>
      <dc:creator>b17gunnr</dc:creator>
      <dc:date>2025-08-25T22:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco encore Events with no Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752200#M119442</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308735"&gt;@b17gunnr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want Splunk to stop searching for timestamps, just go to your Indexer or Heavy Forwarder (whichever is doing the parsing) and update the props.conf for the relevant sourcetype&lt;/P&gt;&lt;P&gt;Eg:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
DATETIME_CONFIG = NONE
SHOULD_LINEMERGE = false
NO_BINARY_CHECK = true&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Tells Splunk not to attempt timestamp extraction. It will use the index time as the event time&lt;/P&gt;&lt;P&gt;Note: Are you using any specific add-on for this?&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 04:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752200#M119442</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-08-26T04:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco encore Events with no Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752203#M119443</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308735"&gt;@b17gunnr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Cisco Firepower app in Splunkbase doesnt have a props.conf to tell Splunk how to process timestamps so you will need to create a props.conf in the appropriate place and deploy out as per your other apps to the server that the data is parsed on (either Heavy Forwarder or Indexer(s)) - this will tell Splunk to use the receipt time:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Set DATETIME_CONFIG = NONE to prevent the timestamp processor from running. When timestamp processing is off, Splunk Enterprise does not look at the text of the event for the timestamp and instead uses the event time of receipt, the time the event arrives through its input. For file-based inputs, the event timestamp is taken from from the modification time of the input file.

Set DATETIME_CONFIG = CURRENT to assign the current system time to each event as Splunk Enterprise indexes it.
&lt;/LI-CODE&gt;&lt;P&gt;For more info check out &lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.2/configure-timestamps/configure-timestamp-recognition#:~:text=Set%20DATETIME_CONFIG%20%3D%20NONE,Enterprise%20indexes%20it" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.2/configure-timestamps/configure-timestamp-recognition#:~:text=Set%20DATETIME_CONFIG%20%3D%20NONE,Enterprise%20indexes%20it&lt;/A&gt;.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# props.conf - Update sourcetypes accordingly
[cisco:estreamer:log]
DATETIME_CONFIG = NONE

[cisco:estreamer:status]
DATETIME_CONFIG = NONE

[cisco:estreamer:data]
DATETIME_CONFIG = NONE&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 05:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cisco-encore-Events-with-no-Timestamp/m-p/752203#M119443</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-08-26T05:33:17Z</dc:date>
    </item>
  </channel>
</rss>

