<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: props.conf date and time formatting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121822#M25243</link>
    <description>&lt;P&gt;Four-digit years are represented by &lt;CODE&gt;'%Y'&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2014 16:06:51 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2014-01-22T16:06:51Z</dc:date>
    <item>
      <title>props.conf date and time formatting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121818#M25239</link>
      <description>&lt;P&gt;I have log files that I would like to get into Splunk but I'm having trouble due to the way the date and time are formatted in the log file. In the past I have add a few lines to the props.conf on the splunk server. &lt;/P&gt;

&lt;P&gt;Here is what I have in the props.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/pathtofile/logserver_output/LogServer.*]
TIME_PREFIX = ^L
TIME_FORMAT = %y_%m_%d.%H_%M_%S
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is a line from the log file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;L2014_01_22.09_35_17{CONVERTED=TRUE,ENE_TIME=0.003,RECORD_NAMES=Record54B43821-6D76-40B6-B5AD-9794DCF445F0,SESSION_ID=acca42e8-3c0f-4b9a-b252-a587dc4de3fb,TYPE=R}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It should be "L" "year" "month" "day" "." "hour" "minute" "second".&lt;/P&gt;

&lt;P&gt;Did I miss something? I am using a test index but it doesn't seem to be reading the date and time correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 15:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121818#M25239</guid>
      <dc:creator>khhenderson</dc:creator>
      <dc:date>2014-01-22T15:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf date and time formatting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121819#M25240</link>
      <description>&lt;P&gt;I believe you need a capital y: %Y&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 16:01:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121819#M25240</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-01-22T16:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf date and time formatting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121820#M25241</link>
      <description>&lt;P&gt;What about month and minute, should they both be capital?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 16:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121820#M25241</guid>
      <dc:creator>khhenderson</dc:creator>
      <dc:date>2014-01-22T16:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf date and time formatting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121821#M25242</link>
      <description>&lt;P&gt;nope, those looks good, here is a reference : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/SearchReference/Commontimeformatvariables"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.1/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 16:06:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121821#M25242</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-01-22T16:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf date and time formatting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121822#M25243</link>
      <description>&lt;P&gt;Four-digit years are represented by &lt;CODE&gt;'%Y'&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 16:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121822#M25243</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-01-22T16:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf date and time formatting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121823#M25244</link>
      <description>&lt;P&gt;That did the trick, I knew it was something simple. Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 18:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-conf-date-and-time-formatting/m-p/121823#M25244</guid>
      <dc:creator>khhenderson</dc:creator>
      <dc:date>2014-01-22T18:49:01Z</dc:date>
    </item>
  </channel>
</rss>

