<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I would like to get some help to process the following timestamp, included in the example, please: in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147639#M30060</link>
    <description>&lt;P&gt;You may need to add a &lt;CODE&gt;TZ&lt;/CODE&gt; statement to your props file, but your problem appears to be more than that.  I wonder if Splunk has a bug processing the &lt;CODE&gt;%b&lt;/CODE&gt; format string if it is not delimited.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Oct 2014 19:42:46 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2014-10-01T19:42:46Z</dc:date>
    <item>
      <title>I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147633#M30054</link>
      <description>&lt;P&gt;The following is one event of the data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MACUL     DIRP101 JUL14 00:00:00 5577 INFO DIRP_FLOW_LOG REASON= 15 SSYS#= 2   
           SSNAME= OM   POOL#= 4 VOLUME#= 68 SOS_FILE_ID= 2949 0005 003C   
           TEXT1= SCHEDULED OG ROTATE COMPLETED, RECORDS: 46628    PARM1= 1978   
           TEXT2= VOL: D050OM3, FILE: A140913000088OM, ROTATE:     PARM2= 2A67
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried using timestamps tab when indexing the data, with not succesful results. I think I have been doing something wrong.&lt;/P&gt;

&lt;P&gt;Thanks in advanced!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 12:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147633#M30054</guid>
      <dc:creator>fvasquezchacon</dc:creator>
      <dc:date>2014-10-01T12:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147634#M30055</link>
      <description>&lt;P&gt;Hello. Can you tell us exactly which is the timestamp in the example? Is the event multiline exactly as shown? Do your events look all the same? (Same format, same line length, same begin string, ...)&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 13:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147634#M30055</guid>
      <dc:creator>felipetesta</dc:creator>
      <dc:date>2014-10-01T13:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147635#M30056</link>
      <description>&lt;P&gt;Is 'JUL14 00:00:00' the timestamp field?  If so, does it represent 14th July of the current year or something else?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 13:39:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147635#M30056</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-01T13:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147636#M30057</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;Thanks for the quick answer.&lt;/P&gt;

&lt;P&gt;In relation to your questions, the time stamp is: "JUL14 00:00:00".&lt;/P&gt;

&lt;P&gt;In fact, the event is multiline. They do not have the same format and line length (unfortunately). They do begin with the word "MACUL" in this log, but the following strings can vary.&lt;/P&gt;

&lt;P&gt;The timestamp represents 14th July of the current year.&lt;/P&gt;

&lt;P&gt;In addition, this logs come from a Huawei Softx300 softswitch. &lt;/P&gt;

&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 15:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147636#M30057</guid>
      <dc:creator>fvasquezchacon</dc:creator>
      <dc:date>2014-10-01T15:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147637#M30058</link>
      <description>&lt;P&gt;Try adding the following to the appropriate stanza of your props.conf file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE = MACUL
TIME_FORMAT = %b%d %H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Oct 2014 17:11:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147637#M30058</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-01T17:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147638#M30059</link>
      <description>&lt;P&gt;Thanks for the answer, but unfortunately it seems not to be working as expected.&lt;/P&gt;

&lt;P&gt;I click on the advanced mode (props.conf) tab and paste the stanza recieved. Bellow there is the result given for the timestamp:&lt;/P&gt;

&lt;P&gt;9/25/01 4:51:20.000 PM&lt;/P&gt;

&lt;P&gt;Did I do it correctly? I have read about editing the props.conf, but I haven't worked with this yet. I would apreciate you could tell me if I'm doing OK please.&lt;/P&gt;

&lt;P&gt;Thanks! &lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 18:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147638#M30059</guid>
      <dc:creator>fvasquezchacon</dc:creator>
      <dc:date>2014-10-01T18:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147639#M30060</link>
      <description>&lt;P&gt;You may need to add a &lt;CODE&gt;TZ&lt;/CODE&gt; statement to your props file, but your problem appears to be more than that.  I wonder if Splunk has a bug processing the &lt;CODE&gt;%b&lt;/CODE&gt; format string if it is not delimited.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2014 19:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147639#M30060</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-01T19:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147640#M30061</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;Thanks for your help. It was very usefull in order to solve this issue.&lt;/P&gt;

&lt;P&gt;As we reviewed, I had some problems but with this settings on the timestamp tab, it worked:&lt;/P&gt;

&lt;P&gt;Location: Timestamp is always prefaced by pattern: MACUL\s+\S+\s&lt;/P&gt;

&lt;P&gt;Format: Timestamp format (strptime): %b%d %H:%M:%S&lt;/P&gt;

&lt;P&gt;On the preview sreen, it seems to not work well (the result was not OK), nevertheless I continued indexing and the result was different and it worked.,Hi!&lt;/P&gt;

&lt;P&gt;Thanks for your help. It was very usefull in order to solve this issue.&lt;/P&gt;

&lt;P&gt;As we reviewed, I had some problems but with this settings on the timestamp tab, it worked:&lt;/P&gt;

&lt;P&gt;Location: Timestamp is always prefaced by pattern: MACUL\s+\S+\s&lt;/P&gt;

&lt;P&gt;Format: Timestamp format (strptime): %b%d %H:%M:%S&lt;/P&gt;

&lt;P&gt;On the preview sreen, it seems to not work well (the result was not OK), nevertheless I continued indexing and the result was different and it worked.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147640#M30061</guid>
      <dc:creator>fvasquezchacon</dc:creator>
      <dc:date>2014-10-03T14:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147641#M30062</link>
      <description>&lt;P&gt;I'm glad you got it working.  Please accept the answer to help others in future.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147641#M30062</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-03T14:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147642#M30063</link>
      <description>&lt;P&gt;Sorry, but I don't know why the backslash symbol does not appear in my post. For the location pattern, the correct stanza is:&lt;/P&gt;

&lt;P&gt;Location: Timestamp is always prefaced by pattern: MACUL(backslash)s+(backslash)S+(backslash)s&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147642#M30063</guid>
      <dc:creator>fvasquezchacon</dc:creator>
      <dc:date>2014-10-03T14:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: I would like to get some help to process the following timestamp, included in the example, please:</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147643#M30064</link>
      <description>&lt;P&gt;Backslash is the escape character.  To insert a backslash you can either use two backslashes or enclose your text in backtics (`).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2014 14:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-would-like-to-get-some-help-to-process-the-following-timestamp/m-p/147643#M30064</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-03T14:57:52Z</dc:date>
    </item>
  </channel>
</rss>

