<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to capture correct timestamp? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25015#M4057</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Seems to have problems with it now.It's been working fine for the past few days..&lt;/P&gt;

&lt;P&gt;Sample of the event:
......,EXTENDED_TIMESTAMP="20/08/10 12:59:21.994681 AM +08:00"....&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[myevent]&lt;BR /&gt;
TIME_PREFIX = EXTENDED_TIMESTAMP="&lt;BR /&gt;
TIME_FORMAT = %d/%m/%y %I:%M:%S.%6N %p&lt;BR /&gt;
SHOULD_LINEMERGE = true  &lt;/P&gt;

&lt;P&gt;This morning I've noticed the dates are specified in splunk as:&lt;BR /&gt;
10/12/08&lt;BR /&gt;
12:59:21.994 AM  &lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;</description>
    <pubDate>Fri, 20 Aug 2010 09:22:14 GMT</pubDate>
    <dc:creator>remy06</dc:creator>
    <dc:date>2010-08-20T09:22:14Z</dc:date>
    <item>
      <title>Unable to capture correct timestamp?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25013#M4055</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;

&lt;P&gt;I'm trying to configure splunk to display the time based on the event.&lt;/P&gt;

&lt;P&gt;The event's timestamp format is something like this:&lt;BR /&gt;
EXTENDED_TIMESTAMP="04-AUG-10 12.10.43.720287 AM +08:00"&lt;/P&gt;

&lt;P&gt;I've configured props.conf with this:&lt;BR /&gt;
[myevent]&lt;BR /&gt;
TIME_PREFIX = EXTENDED_TIMESTAMP="&lt;BR /&gt;
TIME_FORMAT = %d-%b-%y %I.%M.%S.%q %p&lt;BR /&gt;
SHOULD_LINEMERGE = true  &lt;/P&gt;

&lt;P&gt;However,splunk occasionally display the wrong time as it translate AM as PM which is wrong.&lt;/P&gt;

&lt;P&gt;Is there anything wrong with the config?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2010 11:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25013#M4055</guid>
      <dc:creator>remy06</dc:creator>
      <dc:date>2010-08-04T11:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to capture correct timestamp?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25014#M4056</link>
      <description>&lt;P&gt;Hi Remy06,&lt;/P&gt;

&lt;P&gt;Please try TIME_FORMAT = %d-%b-%y %I.%M.%S.%6N %p&lt;/P&gt;

&lt;P&gt;I think it might be the difference between nano and milliseconds that's tripping it up.&lt;/P&gt;

&lt;P&gt;For more detail check &lt;A href="http://www.splunk.com/base/Documentation/4.1.4/admin/Configuretimestamprecognition" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.4/admin/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2010 14:50:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25014#M4056</guid>
      <dc:creator>stephanbuys</dc:creator>
      <dc:date>2010-08-04T14:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to capture correct timestamp?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25015#M4057</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Seems to have problems with it now.It's been working fine for the past few days..&lt;/P&gt;

&lt;P&gt;Sample of the event:
......,EXTENDED_TIMESTAMP="20/08/10 12:59:21.994681 AM +08:00"....&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[myevent]&lt;BR /&gt;
TIME_PREFIX = EXTENDED_TIMESTAMP="&lt;BR /&gt;
TIME_FORMAT = %d/%m/%y %I:%M:%S.%6N %p&lt;BR /&gt;
SHOULD_LINEMERGE = true  &lt;/P&gt;

&lt;P&gt;This morning I've noticed the dates are specified in splunk as:&lt;BR /&gt;
10/12/08&lt;BR /&gt;
12:59:21.994 AM  &lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2010 09:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-capture-correct-timestamp/m-p/25015#M4057</guid>
      <dc:creator>remy06</dc:creator>
      <dc:date>2010-08-20T09:22:14Z</dc:date>
    </item>
  </channel>
</rss>

