<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get Apache access logs to index with the correct timestamp (strptime)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135051#M27799</link>
    <description>&lt;P&gt;Make sure you're putting the settings on the right place (indexer vs forwarder): &lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Sep 2014 01:22:54 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2014-09-23T01:22:54Z</dc:date>
    <item>
      <title>How to get Apache access logs to index with the correct timestamp (strptime)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135046#M27794</link>
      <description>&lt;P&gt;v5.0.4 indexers&lt;/P&gt;

&lt;P&gt;I'm trying to get some Apache access logs to index with the correct timestamp, but no matter what I try, I can't get the date/time to be recognized correctly.&lt;/P&gt;

&lt;P&gt;Example log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://community.splunk.com/www.somesite.com" target="test_blank"&gt;www.somesite.com&lt;/A&gt; somestuff somemorestuff 192.168.1.1 2014-09-22 08:26:39 CDT 200 200 15416 - HTTP "GET blah" some more stuff
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've applied the following in props.conf to the sourcetype:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[thisparticular:apacheaccess]
MAX_TIMESTAMP_LOOKAHEAD=19
NO_BINARY_CHECK=1
SHOULD_LINEMERGE=false
TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=(?:\d{1,3}\.){3}\d{1,3}\s
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The preview highlights the date and time as being found, but with a bit of a mixed up timestamp:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;9/20/01 7:22:39.000 AM
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'd prefer having the timestamp first in the raw log (which is still an option for me), but I want to exhaust efforts in trying to get the above to work before making a change to the log format.&lt;/P&gt;

&lt;P&gt;Am I missing something simple here?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 14:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135046#M27794</guid>
      <dc:creator>cmaier</dc:creator>
      <dc:date>2014-09-22T14:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Apache access logs to index with the correct timestamp (strptime)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135047#M27795</link>
      <description>&lt;P&gt;remove this:&lt;/P&gt;

&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD=19&lt;/P&gt;

&lt;P&gt;from your props.conf.  &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:39:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135047#M27795</guid>
      <dc:creator>jimodonald</dc:creator>
      <dc:date>2020-09-28T17:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Apache access logs to index with the correct timestamp (strptime)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135048#M27796</link>
      <description>&lt;P&gt;No luck jimodonald.  In fact, I'm also testing the input on a 6.x platform and get similar results (they don't even offer the "MAX_TIMESTAMP_LOOKAHEAD" option in the 6.x preview).&lt;/P&gt;

&lt;P&gt;Here's what it looks like in 6.x with similarly mixed up results:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[thisparticular:apacheaccess]
NO_BINARY_CHECK=1
SHOULD_LINEMERGE=false
TIME_FORMAT=%Y-%m-%d %H:%M:%S
TIME_PREFIX=\s(?:\d{1,3}\.){3}\d{1,3}\s
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;On the above in 6.x, a log with "2014-09-22 08:26:39" yields a timestamp of "9/20/01 6:05:29.000 AM"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135048#M27796</guid>
      <dc:creator>cmaier</dc:creator>
      <dc:date>2020-09-28T17:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Apache access logs to index with the correct timestamp (strptime)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135049#M27797</link>
      <description>&lt;P&gt;If it's just the timezone, you can specify the timezone in props.conf with &lt;/P&gt;

&lt;P&gt;TZ=US/Central&lt;/P&gt;

&lt;P&gt;Alternatively Splunk usually does a good job with finding the timestamps on its own.  Splunk is typically good about knowing how to parse the Apache logs. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Listofpretrainedsourcetypes"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Listofpretrainedsourcetypes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 15:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135049#M27797</guid>
      <dc:creator>jimodonald</dc:creator>
      <dc:date>2014-09-22T15:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Apache access logs to index with the correct timestamp (strptime)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135050#M27798</link>
      <description>&lt;P&gt;Oddly enough, a timezone issue is actually what led me to where I am currently.  I was trying to apply a timezone offset to the sourcetype and that's when I realized it wasn't even grabbing the event time from the log - it's using the default indexer time.&lt;/P&gt;

&lt;P&gt;As soon as I can get it to grab the time correctly from the log, I should be able to apply the offset as needed.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 16:04:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135050#M27798</guid>
      <dc:creator>cmaier</dc:creator>
      <dc:date>2014-09-22T16:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Apache access logs to index with the correct timestamp (strptime)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135051#M27799</link>
      <description>&lt;P&gt;Make sure you're putting the settings on the right place (indexer vs forwarder): &lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2014 01:22:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Apache-access-logs-to-index-with-the-correct/m-p/135051#M27799</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-09-23T01:22:54Z</dc:date>
    </item>
  </channel>
</rss>

