<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parsing timestamp that is relative from zero from an embedded device in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91461#M19019</link>
    <description>&lt;P&gt;You need a reference time - any time source will do according to its accuracy. Without a reference time you're out of luck.  You need a reference time.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2014 03:48:25 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2014-01-22T03:48:25Z</dc:date>
    <item>
      <title>Parsing timestamp that is relative from zero from an embedded device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91458#M19016</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I'm new to Splunk and have what I think is a strange use case (maybe not!).  We are capturing logs from an embedded device without a battery powered clock and therefore when booted the device has no reference to the current time.  It generates logs from a time of 0 and timestamps the log events with a time offset in &lt;SECONDS&gt;.&lt;MILLISECONDS&gt; e.g. 9.307.  &lt;/MILLISECONDS&gt;&lt;/SECONDS&gt;&lt;/P&gt;

&lt;P&gt;The device does generally get a time reference quite soon after boot from NTP (if network connected) in the log, so I could pre-process the logs, parse out the time and write a valid timestamp for each event by recalculating the offset.&lt;/P&gt;

&lt;P&gt;Does anyone have any recommendations?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Robert&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2012 22:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91458#M19016</guid>
      <dc:creator>WiredBob</dc:creator>
      <dc:date>2012-03-13T22:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing timestamp that is relative from zero from an embedded device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91459#M19017</link>
      <description>&lt;P&gt;In this case, I would probably use &lt;CODE&gt;DATETIME_CONFIG=CURRENT&lt;/CODE&gt; and just let the indexed time of the event be close enough... I am assuming you are forwarding these over the network, and they will arrive at the indexer within a few milliseconds of being created on the embedded device.  If not, this will not work.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2012 01:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91459#M19017</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2012-03-14T01:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing timestamp that is relative from zero from an embedded device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91460#M19018</link>
      <description>&lt;P&gt;Thanks for the suggestion, but unfortunately these are logs we pull off the device periodically, not passed in near-real time across the network&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2012 09:25:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91460#M19018</guid>
      <dc:creator>WiredBob</dc:creator>
      <dc:date>2012-03-14T09:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing timestamp that is relative from zero from an embedded device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91461#M19019</link>
      <description>&lt;P&gt;You need a reference time - any time source will do according to its accuracy. Without a reference time you're out of luck.  You need a reference time.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 03:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-timestamp-that-is-relative-from-zero-from-an-embedded/m-p/91461#M19019</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-22T03:48:25Z</dc:date>
    </item>
  </channel>
</rss>

