<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204979#M40479</link>
    <description>&lt;P&gt;This config is search time only&lt;BR /&gt;
Time should be set at index time.&lt;/P&gt;</description>
    <pubDate>Sun, 05 Nov 2017 12:59:06 GMT</pubDate>
    <dc:creator>maraman_splunk</dc:creator>
    <dc:date>2017-11-05T12:59:06Z</dc:date>
    <item>
      <title>How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204973#M40473</link>
      <description>&lt;P&gt;I have read multiple blogs and answers and couldn't find anything that helps. &lt;/P&gt;

&lt;P&gt;The filename will be something like this&lt;CODE&gt;blah_blah_blah....161030.txt&lt;/CODE&gt;&lt;BR /&gt;
I have checked my regex on regex101 and it works perfectly. &lt;/P&gt;

&lt;P&gt;This is what I have, &lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[filedate]
DATETIME_CONFIG = /etc/system/local/datetime.xml
category= Date_time
CHARSET=AUTO
disabled=false
pulldown_type = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Datetime.xml&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;datetime&amp;gt;
  &amp;lt;define name="_masheddate3" extract="year, month, day,"&amp;gt;
        &amp;lt;text&amp;gt; ![CDATA[(?:^|source:|source::).*?([123]\d)([01]\d)([0123]\d)[^0-9]]]  &amp;lt;/text&amp;gt;
  &amp;lt;/define&amp;gt;
  &amp;lt;datePatterns&amp;gt;
        &amp;lt;use name="_masheddate3"/&amp;gt;
  &amp;lt;/datePatterns&amp;gt;
&amp;lt;/datetime&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And this the error message that i get from Splunkd.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;11-03-2016 12:44:36.860 -0400 ERROR AggregatorMiningProcessor - Uncaught exception in Aggregator, skipping an event: Error parsing regex XML file: C:\Program Files\Splunk\etc\system\local\datetime.xml - Couldn't find 'timePatterns' in config data for AggregatorProcessor. - data_source="C:\Users\ComputerName\Documents\Test2\blah_blah161030.txt", data_host="local", data_sourcetype="filedate"&amp;lt;/code&amp;gt;

11-03-2016 12:44:36.860 -0400 ERROR AggregatorMiningProcessor - Uncaught exception in Aggregator, skipping an event: Error parsing regex XML file: C:\Program Files\Splunk\etc\system\local\datetime.xml - Couldn't find 'timePatterns' in config data for AggregatorProcessor. - data_source="C:\Users\ComputerName\Documents\Test2\blah_blah161030.txt", data_host="local", data_sourcetype="filedate"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I know Props.conf is working by looking at this error message, so the only issue is in datetime.xml...&lt;BR /&gt;
The time is irrelevant to me. How do I make Splunk just get the date and ignore the time? If there is anyone that had success in this, please let me know! &lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 17:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204973#M40473</guid>
      <dc:creator>moaf13</dc:creator>
      <dc:date>2016-11-03T17:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204974#M40474</link>
      <description>&lt;P&gt;Update: I was able to fix that error or by pass it by adding, &lt;/P&gt;

&lt;P&gt;&amp;lt;timePatterns&amp;gt;&lt;BR /&gt;
&amp;lt;use name="_masheddate2"/&amp;gt;&lt;BR /&gt;
&amp;lt;/timePatterns&amp;gt;&lt;/P&gt;

&lt;P&gt;However, when that happens, Splunk automatically sets timestamp as none&lt;BR /&gt;
which basically forces it to index it at a current time. &lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 22:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204974#M40474</guid>
      <dc:creator>moaf13</dc:creator>
      <dc:date>2016-11-03T22:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204975#M40475</link>
      <description>&lt;P&gt;I would not mess with datetime, unless really required. This should be able to set your day, month year (I think:)) :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-time = (?\d{8}) in source
EVAL-_time = strptime(time,"%Y%m%d”)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It has been a while since i used this, but it might help. Note that the time of day for each event in that file will be midnight.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 15:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204975#M40475</guid>
      <dc:creator>sshelly_splunk</dc:creator>
      <dc:date>2016-11-04T15:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204976#M40476</link>
      <description>&lt;P&gt;guess you would need masheddate3 and not masheddate2&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 09:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204976#M40476</guid>
      <dc:creator>kjetilho</dc:creator>
      <dc:date>2016-11-17T09:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204977#M40477</link>
      <description>&lt;P&gt;Um, doesn't setting this at search time have a pretty significant performance implication?   Additionally, since data is stored in reverse TIME order (emphasis on &lt;STRONG&gt;time&lt;/STRONG&gt;) in the index, this means that what your search pull back will be based on the initial &lt;CODE&gt;_time&lt;/CODE&gt; field (as it was stored in the index) and NOT search-time extracted &lt;CODE&gt;_time&lt;/CODE&gt; field shown above.&lt;/P&gt;

&lt;P&gt;I strongly recommend avoiding this solution.  It's find if you want to extract it with some OTHER name, just don't use "_time".&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 00:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204977#M40477</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2017-02-02T00:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204978#M40478</link>
      <description>&lt;P&gt;Thanks it worked&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 20:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204978#M40478</guid>
      <dc:creator>abhishekdharga</dc:creator>
      <dc:date>2017-11-03T20:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204979#M40479</link>
      <description>&lt;P&gt;This config is search time only&lt;BR /&gt;
Time should be set at index time.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Nov 2017 12:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204979#M40479</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2017-11-05T12:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit my datetime.xml to extract the date from a filename to use as the date for indexed events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204980#M40480</link>
      <description>&lt;P&gt;I think Splunk complain because you don't specify any time in your datetime.xml&lt;BR /&gt;
so you should add something that just set a time to a known value (perhaps at 00:00:00)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   1 &amp;lt;define name="Your Custom Name Time" &amp;gt;
   2          &amp;lt;text&amp;gt;set your time to 00:00:00 here&amp;lt;/text&amp;gt;
   3  &amp;lt;/define&amp;gt;
   4  
   5  &amp;lt;timePatterns&amp;gt;
   6       &amp;lt;use name="Your Custom Name Time"/&amp;gt;
   7 &amp;lt;/timePatterns&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 05 Nov 2017 13:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-edit-my-datetime-xml-to-extract-the-date-from-a-filename/m-p/204980#M40480</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2017-11-05T13:13:32Z</dc:date>
    </item>
  </channel>
</rss>

