<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure props.conf for Splunk to recognize all timestamps in these logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173409#M34886</link>
    <description>&lt;P&gt;You just need a TIME_FORMAT. The time stamp is occurring about 90 chars in, which is below the default MAX_TIMESTAMP_LOOKAHEAD of 128 chars. A suggested format reads as "%m/%d/%Y %H:%M:%S.%3N".&lt;/P&gt;

&lt;P&gt;Splunk is probably confused by the epoch time in milliseconds (with 7 more sigfigs of sub-millisecond appended) occurring in second position. Set the TIME_FORMAT explicitly and you should be in good shape.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Oct 2014 17:36:42 GMT</pubDate>
    <dc:creator>sowings</dc:creator>
    <dc:date>2014-10-21T17:36:42Z</dc:date>
    <item>
      <title>How to configure props.conf for Splunk to recognize all timestamps in these logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173408#M34885</link>
      <description>&lt;P&gt;Splunk is not recognizing the timestamps in these logs.  Some are picked up but others are grouped together into a single entry.&lt;BR /&gt;
actual time stamp is in this format: 10/06/2014 10:34:36.595&lt;BR /&gt;
Can you help provide the stanza needed for props.conf&lt;/P&gt;

&lt;P&gt;15.184.187.23.1412616876595.2742797,15.184.187.23.1412616876595.2742797.HOOSd,18,0,HOOSd,10/06/2014 10:34:36.595&lt;BR /&gt;
15.184.187.23.1412616899080.2742802,15.184.187.23.1412616899080.2742802.HOOSd,12,0,HOOSd,10/06/2014 10:34:59.080&lt;BR /&gt;
15.184.187.23.1412616837048.2742766,15.184.187.23.1412616837048.2742766.ReconfirmSd,10,2,ReconfirmSd,10/06/2014 10:35:13.939&lt;BR /&gt;
15.184.187.23.1412616837048.2742766,15.184.187.23.1412616837048.2742766.SelfServiceMainSd,15,1,SelfServiceMainSd,10/06/2014 10:34:23.845&lt;BR /&gt;
15.184.187.23.1412616944893.2742809,15.184.187.23.1412616944893.2742809.PlayPrompt,9,0,PlayPrompt,10/06/2014 10:35:44.893&lt;BR /&gt;
15.184.187.23.1412616958018.2742810,15.184.187.23.1412616958018.2742810.PlayPrompt,4,0,PlayPrompt,10/06/2014 10:35:58.018&lt;BR /&gt;
15.184.187.23.1412616971362.2742811,15.184.187.23.1412616971362.2742811.CVPPlayPromptv2,3,0,CVPPlayPromptv2,10/06/2014 10:36:11.362&lt;BR /&gt;
15.184.187.23.1412616838939.2742772,15.184.187.23.1412616838939.2742772.CancelBookingSd,10,2,CancelBookingSd,10/06/2014 10:35:11.643&lt;BR /&gt;
15.184.187.23.1412616838939.2742772,15.184.187.23.1412616838939.2742772.SelfServiceMainSd,16,1,SelfServiceMainSd,10/06/2014 10:34:21.658&lt;BR /&gt;
15.184.187.23.1412617011284.2742812,15.184.187.23.1412617011284.2742812.HOOSd,0,0,HOOSd,10/06/2014 10:36:51.284&lt;BR /&gt;
15.184.187.23.1412647288591.2742813,15.184.187.23.1412647288591.2742813.CVPgetTestTFN,0,0,CVPgetTestTFN,10/06/2014 19:01:28.591&lt;BR /&gt;
15.184.187.23.1412647444780.2742814,15.184.187.23.1412647444780.2742814.CVPgetTestTFN,0,0,CVPgetTestTFN,10/06/2014 19:04:04.780&lt;BR /&gt;
15.184.187.23.1412647453406.2742815,15.184.187.23.1412647453406.2742815.GetExperienceSd,0,0,GetExperienceSd,10/06/2014 19:04:13.406&lt;BR /&gt;
15.184.187.23.1412647454062.2742816,15.184.187.23.1412647454062.2742816.CVPDefaultsMenu,0,0,CVPDefaultsMenu,10/06/2014 19:04:14.062&lt;BR /&gt;
15.184.187.23.1412647458328.2742817,15.184.187.23.1412647458328.2742817.CVPDefaultsMenu,0,0,CVPDefaultsMenu,10/06/2014 19:04:18.328&lt;BR /&gt;
15.184.187.23.1412647463359.2742818,15.184.187.23.1412647463359.2742818.CVPDefaultsMenu,0,0,CVPDefaultsMenu,10/06/2014 19:04:23.359&lt;BR /&gt;
15.184.187.23.1412647574720.2742819,15.184.187.23.1412647574720.2742819.CVPgetTestTFN,0,0,CVPgetTestTFN,10/06/2014 19:06:14.720&lt;BR /&gt;
15.184.187.23.1412647583798.2742820,15.184.187.23.1412647583798.2742820.GetExperienceSd,0,0,GetExperienceSd,10/06/2014 19:06:23.798&lt;BR /&gt;
15.184.187.23.1412647584548.2742821,15.184.187.23.1412647584548.2742821.CVPDefaultsMenu,0,0,CVPDefaultsMenu,10/06/2014 19:06:24.548&lt;BR /&gt;
15.184.187.23.1412647589798.2742822,15.184.187.23.1412647589798.2742822.CVPDefaultsMenu,0,0,CVPDefaultsMenu,10/06/2014 19:06:29.798&lt;BR /&gt;
15.184.187.23.1412647592095.2742823,15.184.187.23.1412647592095.2742823.CVPDefaultsMenu,0,0,CVPDefaultsMenu,10/06/2014 19:06:32.095&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 17:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173408#M34885</guid>
      <dc:creator>smudge797</dc:creator>
      <dc:date>2014-10-21T17:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure props.conf for Splunk to recognize all timestamps in these logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173409#M34886</link>
      <description>&lt;P&gt;You just need a TIME_FORMAT. The time stamp is occurring about 90 chars in, which is below the default MAX_TIMESTAMP_LOOKAHEAD of 128 chars. A suggested format reads as "%m/%d/%Y %H:%M:%S.%3N".&lt;/P&gt;

&lt;P&gt;Splunk is probably confused by the epoch time in milliseconds (with 7 more sigfigs of sub-millisecond appended) occurring in second position. Set the TIME_FORMAT explicitly and you should be in good shape.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 17:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173409#M34886</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2014-10-21T17:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure props.conf for Splunk to recognize all timestamps in these logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173410#M34887</link>
      <description>&lt;P&gt;So in data preview these three events get grouped together as a single events using:&lt;/P&gt;

&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
TIME_FORMAT = %m/%d/%Y %H:%M:%S.%3N&lt;/P&gt;

&lt;P&gt;15.184.187.23.1412616971362.2742811,15.184.187.23.1412616971362.2742811.CVPPlayPromptv2,3,0,CVPPlayPromptv2,10/06/2014 10:36:11.362&lt;BR /&gt;
15.184.187.23.1412616838939.2742772,15.184.187.23.1412616838939.2742772.CancelBookingSd,10,2,CancelBookingSd,10/06/2014 10:35:11.643&lt;BR /&gt;
15.184.187.23.1412616838939.2742772,15.184.187.23.1412616838939.2742772.SelfServiceMainSd,16,1,SelfServiceMainSd,10/06/2014 10:34:21.658&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173410#M34887</guid>
      <dc:creator>smudge797</dc:creator>
      <dc:date>2020-09-28T17:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure props.conf for Splunk to recognize all timestamps in these logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173411#M34888</link>
      <description>&lt;P&gt;Data preview may be wrong in this case. The other setting you could use is "SHOULD_LINEMERGE = false", since this data appears to be single-event-per-line.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 18:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-props-conf-for-Splunk-to-recognize-all/m-p/173411#M34888</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2014-10-21T18:01:06Z</dc:date>
    </item>
  </channel>
</rss>

