<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Timestamp Events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210212#M41399</link>
    <description>&lt;P&gt;The stanza you need to change in props.conf will be named after the sourcetype of the data.  &lt;/P&gt;

&lt;P&gt;I'm making comment on renjith.nair's response because if you read the documentation you'll understand this.   However i'm also giving you the answer here:&lt;/P&gt;

&lt;P&gt;[sourcetypeName]&lt;BR /&gt;
TIME_PREFIX = ^&lt;BR /&gt;
TIME_FORMAT = %s%3n&lt;/P&gt;

&lt;P&gt;Finally, I must also note this looks like web traffic logs which splunk already has many sourcetypes preconfigured for.  You might benefit more by using the IIS logs or Apache logs sourcetypes.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 08:13:31 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2020-09-29T08:13:31Z</dc:date>
    <item>
      <title>How to Timestamp Events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210209#M41396</link>
      <description>&lt;P&gt;I have an index which is not timestamping the events. I looked in the Docs and it said I have to define it in my props.conf &lt;/P&gt;

&lt;P&gt;If this is true, can someone help me with the correct stanza? &lt;/P&gt;

&lt;P&gt;Here's what a few of my non-timestamped events look like &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1451406708913 172.xx.xx.xx - 160195 98610 3.12 1.19 200 21105 0 8 /graph?node=10904&amp;amp;profiles=roomsOnly

1451406708879 172.xx.xx.xx - 160194 13073 4.50 3.69 200 6 0 8 /graph?node=10930
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Dec 2015 16:43:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210209#M41396</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2015-12-29T16:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to Timestamp Events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210210#M41397</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;More read : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/HowSplunkextractstimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/HowSplunkextractstimestamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2015 16:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210210#M41397</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-29T16:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to Timestamp Events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210211#M41398</link>
      <description>&lt;P&gt;I read those docs before posting here.. It looks like the timestamp is being assigned to some hosts in that index and not assigning a timestamp to other hosts &lt;/P&gt;

&lt;P&gt;How do I get a timestamp on ALL hosts? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2015 17:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210211#M41398</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2015-12-29T17:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to Timestamp Events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210212#M41399</link>
      <description>&lt;P&gt;The stanza you need to change in props.conf will be named after the sourcetype of the data.  &lt;/P&gt;

&lt;P&gt;I'm making comment on renjith.nair's response because if you read the documentation you'll understand this.   However i'm also giving you the answer here:&lt;/P&gt;

&lt;P&gt;[sourcetypeName]&lt;BR /&gt;
TIME_PREFIX = ^&lt;BR /&gt;
TIME_FORMAT = %s%3n&lt;/P&gt;

&lt;P&gt;Finally, I must also note this looks like web traffic logs which splunk already has many sourcetypes preconfigured for.  You might benefit more by using the IIS logs or Apache logs sourcetypes.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:13:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210212#M41399</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T08:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to Timestamp Events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210213#M41400</link>
      <description>&lt;P&gt;Please explain what is meant by ALL hosts?&lt;/P&gt;

&lt;P&gt;Do you have some hosts which are sending this data in without the correct timestamps?  If so check that props.conf is on every indexer and forwarder that is sending the data in, even the universal forwarders.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2015 17:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Timestamp-Events/m-p/210213#M41400</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2015-12-29T17:22:15Z</dc:date>
    </item>
  </channel>
</rss>

