<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are date_* fields are not being extracted from Windows security logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173093#M34816</link>
    <description>&lt;P&gt;Just in the format:   _time = 2015-03-10 09:09:59   and _raw = 03/10/2015 09:09:59 AM....&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2015 22:12:41 GMT</pubDate>
    <dc:creator>wkupersa</dc:creator>
    <dc:date>2015-03-11T22:12:41Z</dc:date>
    <item>
      <title>Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173090#M34813</link>
      <description>&lt;P&gt;We are bringing Windows Security Logs into Splunk via the universal forwarder. All of the events begin with a timestamp. It is evident in the &lt;EM&gt;raw event. However none of the `date&lt;/EM&gt;*` fields populate. I am assuming this must be a common issue since we aren't doing anything special and these are just Windows Events, but I don't see this question posted here already!? &lt;/P&gt;

&lt;P&gt;Do we need to do something special to get the timestamp to parse and get the &lt;CODE&gt;date_*&lt;/CODE&gt; fields to populate on ingestion?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2015 20:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173090#M34813</guid>
      <dc:creator>wkupersa</dc:creator>
      <dc:date>2015-03-09T20:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173091#M34814</link>
      <description>&lt;P&gt;No love here. Can others at least confirm that they experience this issue? &lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2015 14:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173091#M34814</guid>
      <dc:creator>wkupersa</dc:creator>
      <dc:date>2015-03-11T14:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173092#M34815</link>
      <description>&lt;P&gt;Do you see any difference in the timestamp in Splunk (_time) and in raw data? &lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2015 15:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173092#M34815</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-03-11T15:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173093#M34816</link>
      <description>&lt;P&gt;Just in the format:   _time = 2015-03-10 09:09:59   and _raw = 03/10/2015 09:09:59 AM....&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2015 22:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173093#M34816</guid>
      <dc:creator>wkupersa</dc:creator>
      <dc:date>2015-03-11T22:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173094#M34817</link>
      <description>&lt;P&gt;The &lt;CODE&gt;date_*&lt;/CODE&gt; fields come from parsing of timestamps.  They are basically a useful side-effect.  If the timestamp is not parsed, the &lt;CODE&gt;date_*&lt;/CODE&gt; fields will not appear.  Windows event logs come in via a modular input these days.  The modular input sends in the pre-parsed time as it comes from the Windows event log APIs.  So Splunk does not have to do any timestamp parsing, and therefore we don't get the &lt;CODE&gt;date_*&lt;/CODE&gt; fields.&lt;/P&gt;

&lt;P&gt;Cross-links to other similar questions:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/30822/date-hour-not-present-in-wineventlogs.html"&gt;http://answers.splunk.com/answers/30822/date-hour-not-present-in-wineventlogs.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/92087/default-fields-are-not-visible.html#comment-92199"&gt;http://answers.splunk.com/answers/92087/default-fields-are-not-visible.html#comment-92199&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2015 22:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173094#M34817</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2015-03-11T22:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173095#M34818</link>
      <description>&lt;P&gt;The useful side-effect is useful....And missed when not there. I don't know why my initial search didn't reveal those other questions. Thank you very much for your answer!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2015 20:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173095#M34818</guid>
      <dc:creator>wkupersa</dc:creator>
      <dc:date>2015-03-12T20:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why are date_* fields are not being extracted from Windows security logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173096#M34819</link>
      <description>&lt;P&gt;if this is true, why do my splunk servers running windows 2012r2 create the date_* field for there own eventlogs?  they are using the same props.conf and Splunk_TA_windows app.  when I seach there windows log, they return date_* fields. None of my universal forwarders on windows servers 2012r2 or otherwise or my windows 7 clients do.  the only difference I can find is all my servers (Search heads, indexers, mast indexer, deployment server) are running splunk enterprise.  My other systems are running universal forwarders.  I have used universal forwarder 6.4.0, 6.5.0 and am now trying 7.0.0.  it would make sense if NONE of my windows events gave date_* fields....  but they do.  I really would prefer this work to take load of search head parsing days and hours from search to return non-business hour logins.  I can do this using eval to create the fields but it is EXTREMELY slow and search head intensive as it has to return all results the evaluate and parse them.  Vice only returning the valid events from the Index using date_wday and date_hour.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:15:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-date-fields-are-not-being-extracted-from-Windows/m-p/173096#M34819</guid>
      <dc:creator>jfunderburg</dc:creator>
      <dc:date>2020-09-29T16:15:56Z</dc:date>
    </item>
  </channel>
</rss>

