<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When importing a CSV in Splunk Web, how do I automatically extract values from &amp;quot;Month&amp;quot; and &amp;quot;Year&amp;quot; fields into the _time field? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208473#M41081</link>
    <description>&lt;P&gt;Yes, doesn't work&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2015 19:17:52 GMT</pubDate>
    <dc:creator>faramarz</dc:creator>
    <dc:date>2015-10-29T19:17:52Z</dc:date>
    <item>
      <title>When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208471#M41079</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;I'm in the middle of importing a CSV using the Splunk GUI and am attempting to extract, from two different fields titled &lt;STRONG&gt;Month&lt;/STRONG&gt; and &lt;STRONG&gt;Year&lt;/STRONG&gt;, the date in which the timestamp should correlate. &lt;/P&gt;

&lt;P&gt;The first field is titled &lt;STRONG&gt;Month&lt;/STRONG&gt; and contains the month of the input, and the second is titled &lt;STRONG&gt;Year&lt;/STRONG&gt; and contains the Year of the input. Basically, I want to extract that information into the &lt;STRONG&gt;_time&lt;/STRONG&gt; field automatically. Is this possible? An example would be "October" in the &lt;STRONG&gt;Month&lt;/STRONG&gt; field and "2015" in the &lt;STRONG&gt;Year&lt;/STRONG&gt; field. It doesn't seem to recognize that it should be extracting from both fields and combining the information. Thanks for the help! &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/771iD707CA7D4D096374/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 14:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208471#M41079</guid>
      <dc:creator>faramarz</dc:creator>
      <dc:date>2015-10-29T14:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208472#M41080</link>
      <description>&lt;P&gt;Have you tried specifying Timestamp fields without quotes?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 15:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208472#M41080</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-10-29T15:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208473#M41081</link>
      <description>&lt;P&gt;Yes, doesn't work&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 19:17:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208473#M41081</guid>
      <dc:creator>faramarz</dc:creator>
      <dc:date>2015-10-29T19:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208474#M41082</link>
      <description>&lt;P&gt;I wonder if "Timestamp format" and "Timestamp fields" are conflicting.  Have you tried leaving the format field empty?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 19:39:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208474#M41082</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-10-29T19:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208475#M41083</link>
      <description>&lt;P&gt;Tried unsuccessfully. I've tried a bunch of different variations and none seem to work&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 19:41:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208475#M41083</guid>
      <dc:creator>faramarz</dc:creator>
      <dc:date>2015-10-29T19:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208476#M41084</link>
      <description>&lt;P&gt;Any chance you can put your header line and a couple of lines of the CSV into a pastebin or gist?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 20:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208476#M41084</guid>
      <dc:creator>nnmiller</dc:creator>
      <dc:date>2015-10-29T20:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208477#M41085</link>
      <description>&lt;P&gt;Not sure If you've already got this working but the problem looks to be the comma in the TIME_FORMAT.  Since you've told SPlunk the date stamp fields already you do not need to use a comma.  So it should look like the following instead.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIMESTAMP_FIELDS = Month, Year
TIME_FORMAT = %B %Y
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or, even &lt;CODE&gt;TIME_FORMAT = %B%n%Y&lt;/CODE&gt;,  where %n is for whitespace.&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 22:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208477#M41085</guid>
      <dc:creator>gcato</dc:creator>
      <dc:date>2015-11-02T22:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208478#M41086</link>
      <description>&lt;P&gt;Hi faramarz, did you get this working? What was the solution?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 03:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208478#M41086</guid>
      <dc:creator>gcato</dc:creator>
      <dc:date>2015-11-05T03:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208479#M41087</link>
      <description>&lt;P&gt;Got it working by just running a script to change the fields into a conglomerated field so it looked like "October 1 2015" etc. Don't think it's possible with only a month and year field. &lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 16:16:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208479#M41087</guid>
      <dc:creator>faramarz</dc:creator>
      <dc:date>2015-11-05T16:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: When importing a CSV in Splunk Web, how do I automatically extract values from "Month" and "Year" fields into the _time field?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208480#M41088</link>
      <description>&lt;P&gt;Thanks for the update.  I've tested my solution on 6.3 and it definitely works okay with month and years fields. But your method is just as good if you can adjust the input.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 20:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-importing-a-CSV-in-Splunk-Web-how-do-I-automatically/m-p/208480#M41088</guid>
      <dc:creator>gcato</dc:creator>
      <dc:date>2015-11-05T20:08:28Z</dc:date>
    </item>
  </channel>
</rss>

