<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timestamp format of the input files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166862#M33798</link>
    <description>&lt;P&gt;Can you post your props.conf settings&lt;/P&gt;</description>
    <pubDate>Fri, 01 Aug 2014 07:44:31 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2014-08-01T07:44:31Z</dc:date>
    <item>
      <title>timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166861#M33797</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
when i forward my input files (c:\data) from server A to Splunk Head at ServerB, the date format was correct for all input files as of yesterday. But today, when the date is 1/8/2014 (dd/mm/yyyy), some files from the server A is recognised as 8/1/2014 (dd/mm/yyyy) and some recognised as 1/8/2014 (dd/mm/yyyy). Why is it so? How and where to correct it to ensure the new data format is recognised as dd/mm/yyyy. thks&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2014 07:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166861#M33797</guid>
      <dc:creator>newbiesplunk</dc:creator>
      <dc:date>2014-08-01T07:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166862#M33798</link>
      <description>&lt;P&gt;Can you post your props.conf settings&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2014 07:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166862#M33798</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-01T07:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166863#M33799</link>
      <description>&lt;P&gt;You can do this my mentioning your time format in props.conf file:&lt;/P&gt;

&lt;P&gt;Under your configuration stanza, you can add&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_FORMAT=%d/%m/%Y
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will ensure that the timestamp for all the events of that type are considered in dd/mm/yyyy format.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2014 09:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166863#M33799</guid>
      <dc:creator>keerthana_k</dc:creator>
      <dc:date>2014-08-01T09:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166864#M33800</link>
      <description>&lt;P&gt;it works only the first event after restarted the splunk and the subsequent events were returned back to mm/dd/yyyy. ANy thing else need to do? thks&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 08:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166864#M33800</guid>
      <dc:creator>newbiesplunk</dc:creator>
      <dc:date>2014-08-05T08:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166865#M33801</link>
      <description>&lt;P&gt;how come from the same forwarder, the date format is different for different input files? So strange.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 08:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166865#M33801</guid>
      <dc:creator>newbiesplunk</dc:creator>
      <dc:date>2014-08-05T08:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166866#M33802</link>
      <description>&lt;P&gt;Can you paste your props.conf setting?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 08:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166866#M33802</guid>
      <dc:creator>keerthana_k</dc:creator>
      <dc:date>2014-08-05T08:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp format of the input files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166867#M33803</link>
      <description>&lt;P&gt;You might have to configure other attributes for your sourcetype for timestamp recognition and event-breaking. Please provide some sample logs and current sourcetype definition from props.conf (if any, from indexer).&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 13:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-format-of-the-input-files/m-p/166867#M33803</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-05T13:21:27Z</dc:date>
    </item>
  </channel>
</rss>

