<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timestamp parsing Failing !!! pls help in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146487#M29846</link>
    <description>&lt;P&gt;are you manually importing Webtrends SDC log files into SPLUNK? If so, try using the SPLUNK forwarder.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2016 16:48:46 GMT</pubDate>
    <dc:creator>spammenot66</dc:creator>
    <dc:date>2016-03-17T16:48:46Z</dc:date>
    <item>
      <title>Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146479#M29838</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;All of a sudden, Timestamp parsing doesn't work in splunk when I index a file manually into the system. It ignores the logfile time and takes the current system time.&lt;BR /&gt;
It was working well and I don't know suddenly what caused this problem, It's not even able to recognize the earlier indexed files.&lt;BR /&gt;
It just gives the error "Timestamp parsing failed"..&lt;/P&gt;

&lt;P&gt;Same case for event breaking too, it doesn't work either...&lt;/P&gt;

&lt;P&gt;Can you please post a resolution to this ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 18:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146479#M29838</guid>
      <dc:creator>xbbj3nj</dc:creator>
      <dc:date>2014-04-29T18:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146480#M29839</link>
      <description>&lt;P&gt;sample logs and props.conf setting please&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 19:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146480#M29839</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-04-29T19:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146481#M29840</link>
      <description>&lt;P&gt;Below is the props.conf under /opt/splunk/etc/system/default&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
CHARSET = UTF-8&lt;BR /&gt;
LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
TRUNCATE = 10000&lt;BR /&gt;
DATETIME_CONFIG = /etc/datetime.xml&lt;BR /&gt;
ANNOTATE_PUNCT = True&lt;BR /&gt;
HEADER_MODE =&lt;BR /&gt;
MAX_DAYS_HENCE=2&lt;BR /&gt;
MAX_DAYS_AGO=2000&lt;BR /&gt;
MAX_DIFF_SECS_AGO=3600&lt;BR /&gt;
MAX_DIFF_SECS_HENCE=604800&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
SHOULD_LINEMERGE = True&lt;BR /&gt;
BREAK_ONLY_BEFORE = &lt;BR /&gt;
BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
MAX_EVENTS = 256&lt;BR /&gt;
MUST_BREAK_AFTER = &lt;BR /&gt;
MUST_NOT_BREAK_AFTER = &lt;BR /&gt;
MUST_NOT_BREAK_BEFORE = &lt;BR /&gt;
TRANSFORMS = &lt;BR /&gt;
SEGMENTATION          = indexing&lt;BR /&gt;
SEGMENTATION-all      = full&lt;BR /&gt;
SEGMENTATION-inner    = inner&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:29:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146481#M29840</guid>
      <dc:creator>xbbj3nj</dc:creator>
      <dc:date>2020-09-28T16:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146482#M29841</link>
      <description>&lt;P&gt;SEGMENTATION-outer    = outer&lt;BR /&gt;
SEGMENTATION-raw      = none&lt;BR /&gt;
SEGMENTATION-standard = standard&lt;BR /&gt;
LEARN_SOURCETYPE      = true&lt;BR /&gt;
maxDist = 100&lt;BR /&gt;
detect_trailing_nulls = false&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146482#M29841</guid>
      <dc:creator>xbbj3nj</dc:creator>
      <dc:date>2020-09-28T16:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146483#M29842</link>
      <description>&lt;P&gt;sample log file :&lt;/P&gt;

&lt;H1&gt;Remark: DCS-p&lt;/H1&gt;

&lt;H1&gt;Software: WebTrends SmartSource Data Collector&lt;/H1&gt;

&lt;H1&gt;Version: 1.0&lt;/H1&gt;

&lt;H1&gt;Date: 2014-04-22 04:47:49&lt;/H1&gt;

&lt;H1&gt;Fields: date time c-ip cs-username cs-host cs-method cs-uri-stem cs-uri-query sc-status sc-bytes cs-version cs(User-Agent) cs(Cookie) cs(Referer) dcs-id&lt;/H1&gt;

&lt;P&gt;2014-04-25 23:31:19 172.24.32.95 xbbjnzp fma.abc.net GET /fma/default.aspx &lt;BR /&gt;
2014-04-25 23:31:31 172.24.32.95 xbbjnzp fma.abc.net GET /fma/default.aspx &lt;BR /&gt;
2014-04-25 23:31:37 172.24.32.95 xbbjnzp fma.abc.net GET /fma/futures/default.aspx &lt;BR /&gt;
2014-04-25 23:31:53 172.24.32.95 xbbjnzp fma.abc.net GET /fma/trades/default.aspx&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 19:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146483#M29842</guid>
      <dc:creator>xbbj3nj</dc:creator>
      <dc:date>2014-04-29T19:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146484#M29843</link>
      <description>&lt;P&gt;where exactly the log starts and ends? the config doesn't look right where these may parameters are mentioned!&lt;/P&gt;

&lt;P&gt;simple &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;SHOULD_LINEMERGE=TRUE&lt;BR /&gt;
TIME_FORMAT=%Y-%m-%d %H:%M:%S&lt;BR /&gt;
BREAK_ONLY_BEFORE_DATE=TRUE&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;should see all the log times.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 20:06:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146484#M29843</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-04-29T20:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146485#M29844</link>
      <description>&lt;P&gt;When you import a file into Splunk, you need to specify a sourcetype and configure sourcetype to correctly identify event breaking and timestamp. Till than if the data format is not in Splunk Standard (start with timestamp) it will show that error in preview screen.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2014 20:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146485#M29844</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-04-29T20:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146486#M29845</link>
      <description>&lt;P&gt;So the actual log file looks more like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#Remark: DCS-p
#Software: WebTrends SmartSource Data Collector     
#Version: 1.0
#Date: 2014-04-22 04:47:49
#Fields: date time c-ip cs-username cs-host cs-method cs-uri-stem cs-uri-query sc-status sc-bytes cs-version cs(User-Agent) cs(Cookie) cs(Referer) dcs-id 
2014-04-25 23:31:19 172.24.32.95 xbbjnzp fma.abc.net GET /fma/default.aspx 
2014-04-25 23:31:31 172.24.32.95 xbbjnzp fma.abc.net GET /fma/default.aspx 
2014-04-25 23:31:37 172.24.32.95 xbbjnzp fma.abc.net GET /fma/futures/default.aspx 
2014-04-25 23:31:53 172.24.32.95 xbbjnzp fma.abc.net GET /fma/trades/default.aspx
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Therefore, I believe that you will want the following stanza in a local &lt;CODE&gt;props.conf&lt;/CODE&gt; - perhaps &lt;CODE&gt;.../etc/system/local/props.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yoursourcetype]
SHOULD_LINEMERGE = false
TIME_FORMAT=%Y-%m-%d %H:%M:%S
PREAMBLE_REGEX = \#
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The last line tells Splunk to ignore lines in the log file that begin with &lt;CODE&gt;#&lt;/CODE&gt;. If you want to index these lines, just leave it off.&lt;/P&gt;

&lt;P&gt;Make sure you specify the proper sourcetype for your inputs. If this problem is affecting multiple sourcetypes, add (or edit) a stanza in &lt;CODE&gt;props.conf&lt;/CODE&gt; for each sourcetype.&lt;/P&gt;

&lt;P&gt;I suspect that Splunk has begun to try to process the header, and that is confusing things.&lt;/P&gt;</description>
      <pubDate>Sat, 03 May 2014 10:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146486#M29845</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-05-03T10:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp parsing Failing !!! pls help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146487#M29846</link>
      <description>&lt;P&gt;are you manually importing Webtrends SDC log files into SPLUNK? If so, try using the SPLUNK forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 16:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-parsing-Failing-pls-help/m-p/146487#M29846</guid>
      <dc:creator>spammenot66</dc:creator>
      <dc:date>2016-03-17T16:48:46Z</dc:date>
    </item>
  </channel>
</rss>

