<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SplunkForwarder File Monitor stopped working at 23:59 June 30th 2013 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80643#M16640</link>
    <description>&lt;P&gt;Thanks Ayn.&lt;/P&gt;

&lt;P&gt;Date came in as&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01/07/2013 15:05:29
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk thought is was 7th of januar.&lt;BR /&gt;
Damn US date stamps.&lt;/P&gt;

&lt;P&gt;Corrected this in the props.conf.&lt;BR /&gt;
Added:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mftlogs]
TIME_FORMAT = %d/%m/%Y %H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 01 Jul 2013 13:26:16 GMT</pubDate>
    <dc:creator>ultima</dc:creator>
    <dc:date>2013-07-01T13:26:16Z</dc:date>
    <item>
      <title>SplunkForwarder File Monitor stopped working at 23:59 June 30th 2013</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80641#M16638</link>
      <description>&lt;P&gt;As the title says.&lt;BR /&gt;
Forwarder File Monitor stopped working at 23:59 June 30th 2013&lt;/P&gt;

&lt;P&gt;inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://E:\Logs]
disabled = 0
sourcetype = mftlogs

[WinEventLog:Security]
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Debug:&lt;BR /&gt;
07-01-2013 13:51:05.570 +0200 DEBUG TcpOutputProc - Registering Channel for : source::E:\Logs&amp;lt;removed&amp;gt;.log|host::MFTD|mftlogs|&lt;REMOVED&gt;:9997, oneTimeClient=0, _events.size()=0, _refCount=1, _waitingAckQ.size()=0, _supportsACK=0&lt;BR /&gt;
07-01-2013 13:51:05.570 +0200 DEBUG TcpOutputProc - Unregistering Channel for : source::E:\Logs&amp;lt;removed&amp;gt;.log.log|host::MFTD|mftlogs|&lt;REMOVED&gt;:9997, oneTimeClient=0, _events.size()=1, _refCount=2, _waitingAckQ.size()=0, _supportsACK=0&lt;/REMOVED&gt;&lt;/REMOVED&gt;&lt;/P&gt;

&lt;P&gt;Windows Eventlog still gets inserted into splunk, but not the logs.&lt;BR /&gt;
Anyone ? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2013 12:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80641#M16638</guid>
      <dc:creator>ultima</dc:creator>
      <dc:date>2013-07-01T12:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder File Monitor stopped working at 23:59 June 30th 2013</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80642#M16639</link>
      <description>&lt;P&gt;I suspect this is a timestamp parsing issue. Splunk tries to guess what format the timestamp for a log event is in (unless you tell it explicitly what the format is), and sometimes it guesses wrong. If you do a realtime search you'll see all logs coming in regardless of what timestamp they're assigned, so that might be a thing to do for troubleshooting purposes.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2013 12:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80642#M16639</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-01T12:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder File Monitor stopped working at 23:59 June 30th 2013</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80643#M16640</link>
      <description>&lt;P&gt;Thanks Ayn.&lt;/P&gt;

&lt;P&gt;Date came in as&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01/07/2013 15:05:29
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk thought is was 7th of januar.&lt;BR /&gt;
Damn US date stamps.&lt;/P&gt;

&lt;P&gt;Corrected this in the props.conf.&lt;BR /&gt;
Added:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mftlogs]
TIME_FORMAT = %d/%m/%Y %H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Jul 2013 13:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-File-Monitor-stopped-working-at-23-59-June-30th/m-p/80643#M16640</guid>
      <dc:creator>ultima</dc:creator>
      <dc:date>2013-07-01T13:26:16Z</dc:date>
    </item>
  </channel>
</rss>

