<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209234#M41212</link>
    <description>&lt;P&gt;I am at a loss.  Did you restart Splunk after modifying props.conf?&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2015 14:18:23 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2015-11-04T14:18:23Z</dc:date>
    <item>
      <title>How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209229#M41207</link>
      <description>&lt;P&gt;Hello, Splunkers!&lt;/P&gt;

&lt;P&gt;I'm trying to add a new log file, but I can't extract the correct timestamp.&lt;BR /&gt;
Help me to write any Timestamp format, which will use date and time from events.&lt;BR /&gt;
Here in these 3 sample events, timestamp should be &lt;CODE&gt;01.09.2015 00:20:05&lt;/CODE&gt; for the first event,&lt;BR /&gt;
&lt;CODE&gt;01.09.2015 00:20:05&lt;/CODE&gt; for the second event, and so on.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;tr style="height:21px"&amp;gt;
&amp;lt;td colspan="3" class="s18-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;01.09.15&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s19-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;00:20:05&amp;lt;/td&amp;gt;&amp;lt;td class="s20-90D19DFDD9934A0F8EEAA283057A16E6" style="font-size:1px;background-image:none"&amp;gt; &amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;0.039&amp;lt;/td&amp;gt;&amp;lt;td class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;Мб.&amp;lt;/td&amp;gt;&amp;lt;td class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;Мобильный интернет&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s20-90D19DFDD9934A0F8EEAA283057A16E6" style="font-size:1px;background-image:none"&amp;gt; &amp;lt;/td&amp;gt;&amp;lt;td colspan="5" class="s21-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;0.00&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr style="height:21px"&amp;gt;
&amp;lt;td colspan="3" class="s22-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;01.09.15&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s23-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;00:26:18&amp;lt;/td&amp;gt;&amp;lt;td class="s24-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;900&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s24-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;1&amp;lt;/td&amp;gt;&amp;lt;td class="s24-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;Шт.&amp;lt;/td&amp;gt;&amp;lt;td class="s24-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;Входящее SMS&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s24-90D19DFDD9934A0F8EEAA283057A16E6" style="font-size:1px;background-image:none"&amp;gt; &amp;lt;/td&amp;gt;&amp;lt;td colspan="5" class="s25-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;0.00&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&amp;lt;tr style="height:21px"&amp;gt;
&amp;lt;td colspan="3" class="s18-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;01.09.15&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s19-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;00:26:59&amp;lt;/td&amp;gt;&amp;lt;td class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;900&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;1&amp;lt;/td&amp;gt;&amp;lt;td class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;Шт.&amp;lt;/td&amp;gt;&amp;lt;td class="s20-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;Входящее SMS&amp;lt;/td&amp;gt;&amp;lt;td colspan="2" class="s20-90D19DFDD9934A0F8EEAA283057A16E6" style="font-size:1px;background-image:none"&amp;gt; &amp;lt;/td&amp;gt;&amp;lt;td colspan="5" class="s21-90D19DFDD9934A0F8EEAA283057A16E6"&amp;gt;0.00&amp;lt;/td&amp;gt;
&amp;lt;/tr&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 29 Oct 2015 14:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209229#M41207</guid>
      <dc:creator>shbagautdinov</dc:creator>
      <dc:date>2015-10-29T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209230#M41208</link>
      <description>&lt;P&gt;Something to consider is modifying the datetime_config file or, better yet, create a separate datetime_config file for this sourcetype.  I should emphasize that this is completely untested.&lt;/P&gt;

&lt;P&gt;Copy the existing SPLUNK_HOME/etc/datetime.xml file to SPLUNK_HOME/etc/mydatetime.xml.  Add a new define near the bottom of the file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;define name="mydatetime" extract="month, day, year, hour, minute, second"&amp;gt;
    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;gt;(?P&amp;lt;month&amp;gt;[012]\d)\.(?P&amp;lt;day&amp;gt;[012]\d|3[01])\.(?P&amp;lt;year&amp;gt;\d{2})\&amp;lt;.*?\&amp;gt;(?P&amp;lt;hour&amp;gt;\d{2}):(?P&amp;lt;minute&amp;gt;\d{2}):(?P&amp;lt;second&amp;gt;\d{2})\&amp;lt;]]&amp;gt;&amp;lt;/text&amp;gt;
&amp;lt;/define&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then add `&lt;CODE&gt;to each of the&lt;/CODE&gt;datePatterns&lt;CODE&gt;and&lt;/CODE&gt;timePatterns` stanzas.&lt;/P&gt;

&lt;P&gt;In your props.conf file put:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mysourcetype]
DATETIME_CONFIG = /etc/mydatetime.xml
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209230#M41208</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-29T07:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209231#M41209</link>
      <description>&lt;P&gt;Thank you, man!&lt;BR /&gt;
I have copied the existing SPLUNK_HOME/etc/datetime.xml file to SPLUNK_HOME/etc/megafon.xml. &lt;BR /&gt;
I have added your code&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;define name="megafon" extract=""&amp;gt;
     &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;gt;(?P&amp;lt;month&amp;gt;[012]\d)\.(?P&amp;lt;day&amp;gt;[012]\d|3[01])\.(?P&amp;lt;year&amp;gt;\d{2})\&amp;lt;.*?\&amp;gt;(?P&amp;lt;hour&amp;gt;\d{2}):(?P&amp;lt;minute&amp;gt;\d{2}):(?P&amp;lt;second&amp;gt;\d{2})\&amp;lt;]]&amp;gt;&amp;lt;/text&amp;gt;
 &amp;lt;/define&amp;gt;

&amp;lt;timePatterns&amp;gt;
&amp;lt;use name="megafon"/&amp;gt;
      &amp;lt;use name="_time"/&amp;gt;
      &amp;lt;use name="_hmtime"/&amp;gt;
      &amp;lt;use name="_hmtime"/&amp;gt;
      &amp;lt;use name="_dottime"/&amp;gt;
      &amp;lt;use name="_combdatetime"/&amp;gt;
      &amp;lt;use name="_utcepoch"/&amp;gt;
      &amp;lt;use name="_combdatetime2"/&amp;gt;
&amp;lt;/timePatterns&amp;gt;
&amp;lt;datePatterns&amp;gt;
&amp;lt;use name="megafon"/&amp;gt;
      &amp;lt;use name="_usdate1"/&amp;gt; 
      &amp;lt;use name="_usdate2"/&amp;gt; 
      &amp;lt;use name="_isodate"/&amp;gt;
      &amp;lt;use name="_eurodate1"/&amp;gt; 
      &amp;lt;use name="_eurodate2"/&amp;gt; 
      &amp;lt;use name="_bareurlitdate"/&amp;gt; 
      &amp;lt;use name="_orddate"/&amp;gt;
      &amp;lt;use name="_combdatetime"/&amp;gt;
      &amp;lt;use name="_masheddate"/&amp;gt;
      &amp;lt;use name="_masheddate2"/&amp;gt;
      &amp;lt;use name="_combdatetime2"/&amp;gt;
&amp;lt;/datePatterns&amp;gt;

&amp;lt;/datetime&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have modified &lt;CODE&gt;C:\Program Files\Splunk\etc\apps\search\local\props.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Megafon]
DATETIME_CONFIG = /etc/mydatetime.xml 
NO_BINARY_CHECK = true
category = Custom
disabled = false
pulldown_type = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Source type Megafon was created in Search app context.&lt;/P&gt;

&lt;P&gt;And now it is still only date in the timestamp&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/67181-%D1%81%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209231#M41209</guid>
      <dc:creator>shbagautdinov</dc:creator>
      <dc:date>2020-09-29T07:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209232#M41210</link>
      <description>&lt;P&gt;A modified my answer to include field names in the 'extract' clause.&lt;/P&gt;

&lt;P&gt;Double-check the DATETIME_CONFIG setting in your props.conf.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 12:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209232#M41210</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-10-30T12:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209233#M41211</link>
      <description>&lt;P&gt;Thanks! &lt;BR /&gt;
You found my mistake in my props.conf I have wrote DATETIME_CONFIG = /etc/mydatetime.xml instead of DATETIME_CONFIG = /etc/megafon.xml&lt;BR /&gt;
now name of xml file in etc folder and parameter in DATETIME_CONFIG = are the same&lt;BR /&gt;
In SPLUNK_HOME/etc/megafon.xml I have specified extract &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;define name="megafon" extract="day, month, year, hour, minute, second"&amp;gt;
     &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;gt;(?P&amp;lt;month&amp;gt;[012]\d)\.(?P&amp;lt;day&amp;gt;[012]\d|3[01])\.(?P&amp;lt;year&amp;gt;\d{2})\&amp;lt;.*?\&amp;gt;(?P&amp;lt;hour&amp;gt;\d{2}):(?P&amp;lt;minute&amp;gt;\d{2}):(?P&amp;lt;second&amp;gt;\d{2})\&amp;lt;]]&amp;gt;&amp;lt;/text&amp;gt;
&amp;lt;/define&amp;gt;

&amp;lt;timePatterns&amp;gt;
      &amp;lt;use name="megafon"/&amp;gt;
      &amp;lt;use name="_time"/&amp;gt;
      &amp;lt;use name="_hmtime"/&amp;gt;
      &amp;lt;use name="_hmtime"/&amp;gt;
      &amp;lt;use name="_dottime"/&amp;gt;
      &amp;lt;use name="_combdatetime"/&amp;gt;
      &amp;lt;use name="_utcepoch"/&amp;gt;
      &amp;lt;use name="_combdatetime2"/&amp;gt; 
&amp;lt;/timePatterns&amp;gt;
&amp;lt;datePatterns&amp;gt;
      &amp;lt;use name="megafon"/&amp;gt;
      &amp;lt;use name="_usdate1"/&amp;gt; 
      &amp;lt;use name="_usdate2"/&amp;gt; 
      &amp;lt;use name="_isodate"/&amp;gt;
      &amp;lt;use name="_eurodate1"/&amp;gt; 
      &amp;lt;use name="_eurodate2"/&amp;gt; 
      &amp;lt;use name="_bareurlitdate"/&amp;gt; 
      &amp;lt;use name="_orddate"/&amp;gt;
      &amp;lt;use name="_combdatetime"/&amp;gt;
      &amp;lt;use name="_masheddate"/&amp;gt;
      &amp;lt;use name="_masheddate2"/&amp;gt;
      &amp;lt;use name="_combdatetime2"/&amp;gt;
&amp;lt;/datePatterns&amp;gt;

&amp;lt;/datetime&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But it is still only date in the timestamp&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209233#M41211</guid>
      <dc:creator>shbagautdinov</dc:creator>
      <dc:date>2020-09-29T07:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209234#M41212</link>
      <description>&lt;P&gt;I am at a loss.  Did you restart Splunk after modifying props.conf?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 14:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209234#M41212</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-11-04T14:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure Splunk to extract the timestamp from a new log file I'm trying to index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209235#M41213</link>
      <description>&lt;P&gt;Yes, sure. I have restarted my splunk server several times. The log file is on splunk servers local disk. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 15:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-Splunk-to-extract-the-timestamp-from-a-new/m-p/209235#M41213</guid>
      <dc:creator>shbagautdinov</dc:creator>
      <dc:date>2015-11-04T15:07:37Z</dc:date>
    </item>
  </channel>
</rss>

