<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows server data timestamp issue in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755153#M119830</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268377"&gt;@chandrasekhar46&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;usually Splunk_TA_Windows correctly parse all windows events, even if this seems to be a very strange windows logs that usually have a different format; are these logs windows servers logs or application logs?&lt;/P&gt;&lt;P&gt;Anyway, you should install Splunk_TA_Windows both on UF, HF and SH.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2025 07:48:34 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2025-11-04T07:48:34Z</dc:date>
    <item>
      <title>Windows server data timestamp issue in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755150#M119829</link>
      <description>&lt;P&gt;i have splunk data for windows servers for service but getting timestamp issue here is example error log and event example so how can i use props file&lt;/P&gt;&lt;P&gt;shall i install windows TA addon in HF should resolve it or any custom props file bases on event&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;11-04-2025&lt;/SPAN&gt; &lt;SPAN class=""&gt;06:10:31.452&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0000&lt;/SPAN&gt; &lt;SPAN class=""&gt;WARN&lt;/SPAN&gt; &lt;SPAN class=""&gt;DateParserVerbose&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;1028&lt;/SPAN&gt; &lt;SPAN class=""&gt;winparsing&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;parse&lt;/SPAN&gt; &lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;first&lt;/SPAN&gt; &lt;SPAN class=""&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;128&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;characters&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;event.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Defaulting&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;previous&lt;/SPAN&gt; &lt;SPAN class=""&gt;event&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Tue&lt;/SPAN&gt; &lt;SPAN class=""&gt;Nov&lt;/SPAN&gt; &lt;SPAN class=""&gt;4&lt;/SPAN&gt; &lt;SPAN class=""&gt;06:10:31&lt;/SPAN&gt; &lt;SPAN class=""&gt;2025&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Context:&lt;/SPAN&gt; &lt;SPAN class=""&gt;source=WMI:Service&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;host=XSPW12W923F&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;WMI:Service&lt;/SPAN&gt;&lt;SPAN&gt;|1&lt;BR /&gt;&lt;BR /&gt;event coming like this in splunk :&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;20251104022942.950679&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;DisplayName=test_one&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Name=WdiSystemHost&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;StartMode=Manual&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;State=Stopped&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 07:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755150#M119829</guid>
      <dc:creator>chandrasekhar46</dc:creator>
      <dc:date>2025-11-04T07:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Windows server data timestamp issue in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755153#M119830</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268377"&gt;@chandrasekhar46&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;usually Splunk_TA_Windows correctly parse all windows events, even if this seems to be a very strange windows logs that usually have a different format; are these logs windows servers logs or application logs?&lt;/P&gt;&lt;P&gt;Anyway, you should install Splunk_TA_Windows both on UF, HF and SH.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 07:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755153#M119830</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-11-04T07:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Windows server data timestamp issue in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755154#M119831</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268377"&gt;@chandrasekhar46&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Where have you placed your WQL query for sourcetype="WMI:Service"? It’s recommended to also deploy Splunk_TA_windows on your Heavy Forwarder, as it already includes a parser for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 09:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-server-data-timestamp-issue-in-splunk/m-p/755154#M119831</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-11-04T09:17:05Z</dc:date>
    </item>
  </channel>
</rss>

