<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: timestamp question in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191023#M38028</link>
    <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?r=splunky"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?r=splunky&lt;/A&gt;&lt;BR /&gt;
If Splunk is not auto detecting the timezone, you can force the timezone for a sourcetype as shown in the props documentation linked above; look for TZ = &lt;/P&gt;</description>
    <pubDate>Mon, 17 Mar 2014 14:53:11 GMT</pubDate>
    <dc:creator>starcher</dc:creator>
    <dc:date>2014-03-17T14:53:11Z</dc:date>
    <item>
      <title>timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191020#M38025</link>
      <description>&lt;P&gt;hI,&lt;/P&gt;

&lt;P&gt;Setting up a syslog feed and run into something that I haven't yet:&lt;/P&gt;

&lt;P&gt;2014-03-17T02:02:26-04:00&lt;/P&gt;

&lt;P&gt;What does the T stand for?  The time is one hour behind the current timestamp, so I'm assuming that it's a timezone?  &lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 14:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191020#M38025</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-03-17T14:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191021#M38026</link>
      <description>&lt;P&gt;T stands for time.  the timezone adjustment is the -4:00 at the end.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 14:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191021#M38026</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2014-03-17T14:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191022#M38027</link>
      <description>&lt;P&gt;So, how would I configure that in props.conf?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 14:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191022#M38027</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-03-17T14:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191023#M38028</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?r=splunky"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?r=splunky&lt;/A&gt;&lt;BR /&gt;
If Splunk is not auto detecting the timezone, you can force the timezone for a sourcetype as shown in the props documentation linked above; look for TZ = &lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 14:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191023#M38028</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2014-03-17T14:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191024#M38029</link>
      <description>&lt;P&gt;Thanks. I looked at the doc, but I'm still unclear.  How would you reference the T? Or would you reference the -4:00?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 15:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191024#M38029</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-03-17T15:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191025#M38030</link>
      <description>&lt;P&gt;Splunk can process this format without any props.conf configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 16:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191025#M38030</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-03-17T16:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: timestamp question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191026#M38031</link>
      <description>&lt;P&gt;Don't want to do it without props - trying to follow the recommended guidelines - configuring time_zone, time_format....&lt;/P&gt;

&lt;P&gt;Here's what I have:&lt;/P&gt;

&lt;P&gt;[acme_syslog]&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 30&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
TIME_FORMAT = %y-%m-%dT%H:%M:%S&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TIME_PREFIX = ^&lt;BR /&gt;
LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;
TZ = US/Central&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:09:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/timestamp-question/m-p/191026#M38031</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2020-09-28T16:09:44Z</dc:date>
    </item>
  </channel>
</rss>

