<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to parse the date_time and event_time fields from my raw data in PSV format? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-date-time-and-event-time-fields-from-my-raw/m-p/152092#M30959</link>
    <description>&lt;P&gt;You need to tell Splunk how to interpret the timestamp in each event as documented here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Handleeventtimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Handleeventtimestamps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Just by looking at your event, I have no idea how to interpret your timestamps so I assume Splunk is treating them as &lt;CODE&gt;epoch&lt;/CODE&gt; which is giving a time way in the past.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jun 2015 16:40:23 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-06-09T16:40:23Z</dc:date>
    <item>
      <title>How to parse the date_time and event_time fields from my raw data in PSV format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-date-time-and-event-time-fields-from-my-raw/m-p/152091#M30958</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;

&lt;P&gt;i have some mainframe logs coming into splunk which is in PSV (pipe separated value) format.  have managed to parse all of the data successfully, but the &lt;CODE&gt;date_time&lt;/CODE&gt; and &lt;CODE&gt;Event_time&lt;/CODE&gt; fields are showing dates as 31 dec, 1969 and 1970, but in the log file, it's dated april to june of 2015. &lt;/P&gt;

&lt;P&gt;sample log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;IN|15080|830828|V014MSNY|B014MU01|CAL0Q14|DPNT1|PSABTSR1|||0000000|DDTD34|FAIL|10|012||||x980|USER|
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Jun 2015 15:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-date-time-and-event-time-fields-from-my-raw/m-p/152091#M30958</guid>
      <dc:creator>shivarpith</dc:creator>
      <dc:date>2015-06-09T15:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse the date_time and event_time fields from my raw data in PSV format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-date-time-and-event-time-fields-from-my-raw/m-p/152092#M30959</link>
      <description>&lt;P&gt;You need to tell Splunk how to interpret the timestamp in each event as documented here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Handleeventtimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Handleeventtimestamps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Just by looking at your event, I have no idea how to interpret your timestamps so I assume Splunk is treating them as &lt;CODE&gt;epoch&lt;/CODE&gt; which is giving a time way in the past.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 16:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-date-time-and-event-time-fields-from-my-raw/m-p/152092#M30959</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-09T16:40:23Z</dc:date>
    </item>
  </channel>
</rss>

