<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic received event and Failed to parse timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96801#M20173</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I didn't found the answer. I got splunk 5.0.1 and it worked good!&lt;BR /&gt;
Since I've installed four apps :&lt;BR /&gt;
-TA-cisco_asa&lt;BR /&gt;
-Splunk_for_CiscoASA&lt;BR /&gt;
-maps&lt;BR /&gt;
-sideview_utils&lt;/P&gt;

&lt;P&gt;I restart splunk , I added data syslog with UDP port 514 and I see a yellow bar with :&lt;BR /&gt;
"received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:514' host='host::192.X.X.X' sourcetype='sourcetype::cisco:asa' (1 missing total)"&lt;/P&gt;

&lt;P&gt;And in my splunkd.log we can see : &lt;BR /&gt;
"DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Wed Jan 23 11:29:58 2013). Context: source::514|host::192.X.X.X|syslog|"&lt;/P&gt;

&lt;P&gt;Would I have missed a conf ?&lt;/P&gt;

&lt;P&gt;Thanks to help me !&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:10:09 GMT</pubDate>
    <dc:creator>yoann</dc:creator>
    <dc:date>2020-09-28T13:10:09Z</dc:date>
    <item>
      <title>received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96801#M20173</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I didn't found the answer. I got splunk 5.0.1 and it worked good!&lt;BR /&gt;
Since I've installed four apps :&lt;BR /&gt;
-TA-cisco_asa&lt;BR /&gt;
-Splunk_for_CiscoASA&lt;BR /&gt;
-maps&lt;BR /&gt;
-sideview_utils&lt;/P&gt;

&lt;P&gt;I restart splunk , I added data syslog with UDP port 514 and I see a yellow bar with :&lt;BR /&gt;
"received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:514' host='host::192.X.X.X' sourcetype='sourcetype::cisco:asa' (1 missing total)"&lt;/P&gt;

&lt;P&gt;And in my splunkd.log we can see : &lt;BR /&gt;
"DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Wed Jan 23 11:29:58 2013). Context: source::514|host::192.X.X.X|syslog|"&lt;/P&gt;

&lt;P&gt;Would I have missed a conf ?&lt;/P&gt;

&lt;P&gt;Thanks to help me !&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:10:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96801#M20173</guid>
      <dc:creator>yoann</dc:creator>
      <dc:date>2020-09-28T13:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96802#M20174</link>
      <description>&lt;P&gt;The bar suggests you're trying to write events into an index 'firewall' that doesn't exist.&lt;/P&gt;

&lt;P&gt;Compare your inputs on all forwarders with the indexes on your indexers, they likely don't fit together.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 11:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96802#M20174</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-23T11:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96803#M20175</link>
      <description>&lt;P&gt;yeah , that's why i don't understand in /usr/local/splunk/etc/system/local/ I can see : inputs.conf  README  server.conf  tenants.conf that's all ...&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 12:18:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96803#M20175</guid>
      <dc:creator>yoann</dc:creator>
      <dc:date>2013-01-23T12:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96804#M20176</link>
      <description>&lt;P&gt;system/local is one of many many places configuration files can reside in. It's not enough to check just that one.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 12:23:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96804#M20176</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-23T12:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96805#M20177</link>
      <description>&lt;P&gt;I have to search indexes.conf ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 12:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96805#M20177</guid>
      <dc:creator>yoann</dc:creator>
      <dc:date>2013-01-23T12:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96806#M20178</link>
      <description>&lt;P&gt;Nobody know ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 14:30:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96806#M20178</guid>
      <dc:creator>yoann</dc:creator>
      <dc:date>2013-01-23T14:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96807#M20179</link>
      <description>&lt;P&gt;As Ayn said, there potentially are a million places that may contain configuration. To make sure you need to check each and every one.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 15:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96807#M20179</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-23T15:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: received event and Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96808#M20180</link>
      <description>&lt;P&gt;I proceeded otherwise, I used splunkforward and there is no message now&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 16:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/received-event-and-Failed-to-parse-timestamp/m-p/96808#M20180</guid>
      <dc:creator>yoann</dc:creator>
      <dc:date>2013-01-23T16:06:48Z</dc:date>
    </item>
  </channel>
</rss>

