<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting the timestamp on a log entry in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Setting-the-timestamp-on-a-log-entry/m-p/86892#M18027</link>
    <description>&lt;P&gt;I can't seem to get this working, logs are getting confused about the time format since it is Day Month Year. &lt;/P&gt;

&lt;P&gt;the log is in /var/log/holly/alarms.20120307-001.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07/03/12 17:33:54;test2

more props.conf
[source::/var/log/holly/*alarms*"]
TIME_PREFIX = ^ 
TIME_FORMAT = %d/%m/%y %H:%M:%S;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 07 Mar 2012 22:46:40 GMT</pubDate>
    <dc:creator>imacdonald2</dc:creator>
    <dc:date>2012-03-07T22:46:40Z</dc:date>
    <item>
      <title>Setting the timestamp on a log entry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-the-timestamp-on-a-log-entry/m-p/86892#M18027</link>
      <description>&lt;P&gt;I can't seem to get this working, logs are getting confused about the time format since it is Day Month Year. &lt;/P&gt;

&lt;P&gt;the log is in /var/log/holly/alarms.20120307-001.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07/03/12 17:33:54;test2

more props.conf
[source::/var/log/holly/*alarms*"]
TIME_PREFIX = ^ 
TIME_FORMAT = %d/%m/%y %H:%M:%S;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Mar 2012 22:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-the-timestamp-on-a-log-entry/m-p/86892#M18027</guid>
      <dc:creator>imacdonald2</dc:creator>
      <dc:date>2012-03-07T22:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Setting the timestamp on a log entry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-the-timestamp-on-a-log-entry/m-p/86893#M18028</link>
      <description>&lt;P&gt;If I change the source to [source::/var/log/holly/alarms.*.log] it now works,&lt;BR /&gt;
Grrr. I think I see the typo, the " at the see of the source. &lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2012 00:03:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-the-timestamp-on-a-log-entry/m-p/86893#M18028</guid>
      <dc:creator>imacdonald2</dc:creator>
      <dc:date>2012-03-08T00:03:16Z</dc:date>
    </item>
  </channel>
</rss>

