<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time stamp on custom imported file @Please Help@ in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84541#M17558</link>
    <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3/Data/Configuretimestamprecognition"&gt;Configure timestamp recognition&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Mar 2012 20:31:10 GMT</pubDate>
    <dc:creator>MarioM</dc:creator>
    <dc:date>2012-03-05T20:31:10Z</dc:date>
    <item>
      <title>Time stamp on custom imported file @Please Help@</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84539#M17556</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have never done an import on Splunk, so i'm sorry if this has been asked although I can't find it if it has.&lt;/P&gt;

&lt;P&gt;I am trying to import a web usage log that is in the following format(below). I have tried doing a custom import as it didn't fit any of the preset ones, although when looking in Splunk after indexing the time stamp is completely wrong.&lt;/P&gt;

&lt;P&gt;Tue 03 Jan 2012 10:25:57 AM CET&lt;/P&gt;

&lt;P&gt;Considerations -&lt;BR /&gt;
 * Don't need the day "Tue"&lt;BR /&gt;
 * Month is not a numerical value ie 01 for Jan&lt;BR /&gt;
 * Not in 24hr format so shows AM/PM&lt;BR /&gt;
 * Time on the log was taken in CET, is it possible to convert to GMT London? same as Splunk server&lt;/P&gt;

&lt;P&gt;I really need help on how to configure this please. If anybody can help I would be really greatful, thanks for your time.&lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Guy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2012 18:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84539#M17556</guid>
      <dc:creator>j666gak</dc:creator>
      <dc:date>2012-03-05T18:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp on custom imported file @Please Help@</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84540#M17557</link>
      <description>&lt;P&gt;Splunk is usually very good at parsing timestamps in exactly this format. So, can you show us a few complete events? (anonymizing any private stuff of course) I suspect that Splunk is just confused about where to find the timestamp within the event, not with the format itself.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2012 20:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84540#M17557</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-03-05T20:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp on custom imported file @Please Help@</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84541#M17558</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3/Data/Configuretimestamprecognition"&gt;Configure timestamp recognition&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2012 20:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84541#M17558</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-03-05T20:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Time stamp on custom imported file @Please Help@</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84542#M17559</link>
      <description>&lt;P&gt;BTW, you can tell Splunk that the input is in one of the following known web log formats: &lt;BR /&gt;
access_combined (Apache)&lt;BR /&gt;
access_combined_wcookie (Apache)&lt;BR /&gt;
iis (Microsoft IIS)&lt;/P&gt;

&lt;P&gt;You can find this by choosing More Options, and then setting the value for sourcetype (you will need to select Manual instead of Automatic) to do this.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:28:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-stamp-on-custom-imported-file-Please-Help/m-p/84542#M17559</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2020-09-28T11:28:52Z</dc:date>
    </item>
  </channel>
</rss>

