<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I have different timestamp formats using the same sourcetype? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161070#M32648</link>
    <description>&lt;P&gt;Yes it is possible by having your app specific datetime.xml&lt;/P&gt;

&lt;P&gt;See this&lt;BR /&gt;
&lt;A href="http://"&gt;http://answers.splunk.com/answers/11173/how-to-extact-multiple-timestamp-formats-for-syslog-input&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, there is another website where they have some examples&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://"&gt;http://www.function1.com/2013/01/oh-no-splunking-log-files-with-multiple-formats-no-problem&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2014 09:47:12 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2014-07-29T09:47:12Z</dc:date>
    <item>
      <title>Can I have different timestamp formats using the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161068#M32646</link>
      <description>&lt;P&gt;Indexing a lot of SystemOut.log files from WebSphere I realize that all almost all log files uses the following time format&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_FORMAT = %m/%d/%y %H:%M:%S%3N %Z
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But on some old servers the format is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_FORMAT = %d/%m/%y %H:%M:%S%3N %Z
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is it possible for to use two formats for the same sourcetype? Or as an alternative can I create a "child sourcetype" with no other changes than the time_format? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 09:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161068#M32646</guid>
      <dc:creator>rune_hellem</dc:creator>
      <dc:date>2014-07-29T09:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can I have different timestamp formats using the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161069#M32647</link>
      <description>&lt;P&gt;I don't know if this works in your usecase. But you should be able to use a custom datetime.xml to solve this. Take a look at this: &lt;A href="http://answers.splunk.com/answers/1807/2-different-timestamps-in-single-log"&gt;http://answers.splunk.com/answers/1807/2-different-timestamps-in-single-log&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 09:32:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161069#M32647</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2014-07-29T09:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can I have different timestamp formats using the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161070#M32648</link>
      <description>&lt;P&gt;Yes it is possible by having your app specific datetime.xml&lt;/P&gt;

&lt;P&gt;See this&lt;BR /&gt;
&lt;A href="http://"&gt;http://answers.splunk.com/answers/11173/how-to-extact-multiple-timestamp-formats-for-syslog-input&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, there is another website where they have some examples&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://"&gt;http://www.function1.com/2013/01/oh-no-splunking-log-files-with-multiple-formats-no-problem&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 09:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161070#M32648</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-29T09:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can I have different timestamp formats using the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161071#M32649</link>
      <description>&lt;P&gt;For Windows users, worth noticing how to correctly define path to custom datetime.xml escaping backslashes. Took some time before I figured that one out (use double backslashes, it does not show here)&lt;/P&gt;

&lt;P&gt;DATETIME_CONFIG = \\etc\\apps\\myapp\\local\\datetime.xml&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2014 08:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-have-different-timestamp-formats-using-the-same-sourcetype/m-p/161071#M32649</guid>
      <dc:creator>rune_hellem</dc:creator>
      <dc:date>2014-08-01T08:51:28Z</dc:date>
    </item>
  </channel>
</rss>

