<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk is ignoring timestamp and using indexing time in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82119#M16954</link>
    <description>&lt;P&gt;I'm running into an issue with Splunk ignoring the timestamp in a specific log and just using current indexing time. Example extract(XXXX and #### replace letters and numbers)&lt;/P&gt;

&lt;P&gt;[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_EMAIL_INVOICES_ADDRESS: []&lt;/P&gt;

&lt;P&gt;[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_LANGUAGE_ID: [25]&lt;/P&gt;

&lt;P&gt;[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_DATE_FORMAT_ID: [1]&lt;/P&gt;

&lt;P&gt;Format is %Y-%m-%d-%H-%M-%S&lt;/P&gt;

&lt;P&gt;I've attempted the below dateformat to resolve this (there is a backslash escaping the [ below, it's being removed):&lt;/P&gt;

&lt;P&gt;TIME_PREFIX = [&lt;/P&gt;

&lt;P&gt;TIME_FORMAT = %Y-%m-%d-%H-%M-%S&lt;/P&gt;

&lt;P&gt;Unfortunately, no luck, and it's still showing up with the indexing time.&lt;/P&gt;

&lt;P&gt;Any help on this? I'm running into a wall.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2011 13:13:27 GMT</pubDate>
    <dc:creator>colin_ewen</dc:creator>
    <dc:date>2011-09-27T13:13:27Z</dc:date>
    <item>
      <title>Splunk is ignoring timestamp and using indexing time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82119#M16954</link>
      <description>&lt;P&gt;I'm running into an issue with Splunk ignoring the timestamp in a specific log and just using current indexing time. Example extract(XXXX and #### replace letters and numbers)&lt;/P&gt;

&lt;P&gt;[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_EMAIL_INVOICES_ADDRESS: []&lt;/P&gt;

&lt;P&gt;[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_LANGUAGE_ID: [25]&lt;/P&gt;

&lt;P&gt;[2011-09-27-04-03-54][XXXX::IA::Actions][####]: BUYER_DATE_FORMAT_ID: [1]&lt;/P&gt;

&lt;P&gt;Format is %Y-%m-%d-%H-%M-%S&lt;/P&gt;

&lt;P&gt;I've attempted the below dateformat to resolve this (there is a backslash escaping the [ below, it's being removed):&lt;/P&gt;

&lt;P&gt;TIME_PREFIX = [&lt;/P&gt;

&lt;P&gt;TIME_FORMAT = %Y-%m-%d-%H-%M-%S&lt;/P&gt;

&lt;P&gt;Unfortunately, no luck, and it's still showing up with the indexing time.&lt;/P&gt;

&lt;P&gt;Any help on this? I'm running into a wall.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 13:13:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82119#M16954</guid>
      <dc:creator>colin_ewen</dc:creator>
      <dc:date>2011-09-27T13:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is ignoring timestamp and using indexing time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82120#M16955</link>
      <description>&lt;P&gt;Where exactly did you place these lines of configuration?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 15:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82120#M16955</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-09-27T15:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is ignoring timestamp and using indexing time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82121#M16956</link>
      <description>&lt;P&gt;I added them to the props.conf on the forwarder. Should the props.conf be added to the indexer too, or just the forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 15:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82121#M16956</guid>
      <dc:creator>colin_ewen</dc:creator>
      <dc:date>2011-09-27T15:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is ignoring timestamp and using indexing time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82122#M16957</link>
      <description>&lt;P&gt;Probably: &lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F"&gt;http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 15:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82122#M16957</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-09-27T15:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is ignoring timestamp and using indexing time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82123#M16958</link>
      <description>&lt;P&gt;I've adjusted props.conf on the backend, but it did not work properly. At this point, it now groups them into chunks of 16 lines as a single event and continues to give them the wrong timestamp.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2011 15:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82123#M16958</guid>
      <dc:creator>colin_ewen</dc:creator>
      <dc:date>2011-09-27T15:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk is ignoring timestamp and using indexing time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82124#M16959</link>
      <description>&lt;P&gt;Colin, try placing a ^ (to indicate the beginning of the line) in front of the backslash escaping your left bracket in TIME_PREFIX.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2011 22:23:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-is-ignoring-timestamp-and-using-indexing-time/m-p/82124#M16959</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2011-10-03T22:23:08Z</dc:date>
    </item>
  </channel>
</rss>

