<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting date from filename and time from logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95040#M19807</link>
    <description>&lt;P&gt;Thanks Gerald. I have my own datetime.xml defined already, and it's working great for some events, but for certain events Splunk is pulling the date from some other values in the logs. &lt;/P&gt;

&lt;P&gt;So that is the reason why I'm asking if it's possible to change the timestamp recognition precedence so that it will hit my datetime.xml first before going to some other places to look for the date. &lt;/P&gt;

&lt;P&gt;Thanks for the response though, always appreciative of your help.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Nov 2010 22:08:31 GMT</pubDate>
    <dc:creator>silvermail</dc:creator>
    <dc:date>2010-11-30T22:08:31Z</dc:date>
    <item>
      <title>Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95036#M19803</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am not sure if this is possible, but I have a file named called php_201000618.txt and inside the logs it contain something like:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;----------Time 20:54:17----------&lt;BR /&gt;
  HTTP/1.1 200 OK&lt;BR /&gt;
  Date: Sun, 6 Jun 2010 19:33:17 GMT&lt;BR /&gt;
  Server: Apache&lt;BR /&gt;
  Content-Length: 51&lt;BR /&gt;
  Keep-Alive: timeout=300, max=636&lt;BR /&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I need to get the date from the filename 20100618 and the time from 20:54:17. Is it possible to split the timestamp recognition precedence into two components? &lt;/P&gt;

&lt;P&gt;I know it may seem easier to get it from the line "Date: Sun, 6 Jun 2010 19:33:17 GMT", but this line does not exist in all the lines - and the only reliable place is to get the date from the filename as well as the header "----------Time 20:54:17----------"&lt;/P&gt;

&lt;P&gt;Right now I have a props.conf that shows:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;TIME_PREFIX = ^----------Time&lt;BR /&gt;
  TIME_FORMAT = %H:%M:%S&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Time extraction is working fine, but I am getting some random dates which I am not sure why this is happening.&lt;/P&gt;

&lt;P&gt;Thanks for any suggestions.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2010 14:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95036#M19803</guid>
      <dc:creator>silvermail</dc:creator>
      <dc:date>2010-11-26T14:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95037#M19804</link>
      <description>&lt;P&gt;You may want to take a look at the following answer that has been posted. I believe that it answers your question as well.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/12015/setting-date-on-event-based-on-filename" rel="nofollow"&gt;http://splunk-base.splunk.com/answers/12015/setting-date-on-event-based-on-filename&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2010 21:09:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95037#M19804</guid>
      <dc:creator>Rob</dc:creator>
      <dc:date>2010-11-26T21:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95038#M19805</link>
      <description>&lt;P&gt;Thanks Rob, but the example you have mentioned isn't what I was looking for. Thanks anyway...&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2010 23:13:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95038#M19805</guid>
      <dc:creator>silvermail</dc:creator>
      <dc:date>2010-11-26T23:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95039#M19806</link>
      <description>&lt;P&gt;Try this: &lt;A href="http://blogs.splunk.com/2009/12/02/configure-splunk-to-pull-a-date-out-of-a-non-standard-filename/" rel="nofollow"&gt;http://blogs.splunk.com/2009/12/02/configure-splunk-to-pull-a-date-out-of-a-non-standard-filename/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Yours might not be so complicated, but the general idea holds.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2010 04:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95039#M19806</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-11-30T04:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95040#M19807</link>
      <description>&lt;P&gt;Thanks Gerald. I have my own datetime.xml defined already, and it's working great for some events, but for certain events Splunk is pulling the date from some other values in the logs. &lt;/P&gt;

&lt;P&gt;So that is the reason why I'm asking if it's possible to change the timestamp recognition precedence so that it will hit my datetime.xml first before going to some other places to look for the date. &lt;/P&gt;

&lt;P&gt;Thanks for the response though, always appreciative of your help.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2010 22:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95040#M19807</guid>
      <dc:creator>silvermail</dc:creator>
      <dc:date>2010-11-30T22:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95041#M19808</link>
      <description>&lt;P&gt;There is not, but if you make sure the datetime.xml contains only date formats that will definitely fail in the file, then it &lt;EM&gt;should&lt;/EM&gt; fall through to the filename.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2010 10:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95041#M19808</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-12-01T10:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95042#M19809</link>
      <description>&lt;P&gt;The link provided by Rob has been "updated" to better suit your use-case &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Take a look at it now!&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2011 13:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95042#M19809</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2011-05-23T13:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Getting date from filename and time from logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95043#M19810</link>
      <description>&lt;P&gt;I set TIME_PREFIX TIME_FORMAT and plus LOOK_AHEAD(how long the time string is) then ,it works well.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-date-from-filename-and-time-from-logs/m-p/95043#M19810</guid>
      <dc:creator>kenkenou</dc:creator>
      <dc:date>2020-09-29T11:35:31Z</dc:date>
    </item>
  </channel>
</rss>

