<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure Splunk to set the event timestamp based on filename for date and events for time? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229042#M44556</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I don't know if it is possible get this setup. I should load into Splunk a log file with lots of events, but I am not able to set up the timestamp in the right way. In the filename, I can seen the date and in the events the time as following: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Filename: LOG_14-07-09_1100.TST&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Events sample: &lt;BR /&gt;
11000000 RSM2 MC0210 pcs013 ....&lt;BR /&gt;
11010500 SSM7  MC2020 pkt023 ....&lt;BR /&gt;
11030500 KSF3  MC4010 pkt313 ....&lt;BR /&gt;
11100100 TRW71 MC1010 pkt021 ....&lt;BR /&gt;
11122000 WRM1  MC1020 pkt013 ....&lt;BR /&gt;
11330200 TWM31 MC0410 pkt118 ....&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;So, the timestamp should be: &lt;BR /&gt;
2014/07/09 - 11:00 AM &lt;BR /&gt;
2014/07/09 - 11:01 AM &lt;BR /&gt;
2014/07/09 - 11:03 AM &lt;BR /&gt;
2014/07/09 - 11:10 AM &lt;BR /&gt;
2014/07/09 - 11:12 AM &lt;BR /&gt;
2014/07/09 - 11:33 AM &lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any idea if this is possible? If so, how? &lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:35:16 GMT</pubDate>
    <dc:creator>ofaura</dc:creator>
    <dc:date>2020-09-29T09:35:16Z</dc:date>
    <item>
      <title>How to configure Splunk to set the event timestamp based on filename for date and events for time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229042#M44556</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I don't know if it is possible get this setup. I should load into Splunk a log file with lots of events, but I am not able to set up the timestamp in the right way. In the filename, I can seen the date and in the events the time as following: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Filename: LOG_14-07-09_1100.TST&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Events sample: &lt;BR /&gt;
11000000 RSM2 MC0210 pcs013 ....&lt;BR /&gt;
11010500 SSM7  MC2020 pkt023 ....&lt;BR /&gt;
11030500 KSF3  MC4010 pkt313 ....&lt;BR /&gt;
11100100 TRW71 MC1010 pkt021 ....&lt;BR /&gt;
11122000 WRM1  MC1020 pkt013 ....&lt;BR /&gt;
11330200 TWM31 MC0410 pkt118 ....&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;So, the timestamp should be: &lt;BR /&gt;
2014/07/09 - 11:00 AM &lt;BR /&gt;
2014/07/09 - 11:01 AM &lt;BR /&gt;
2014/07/09 - 11:03 AM &lt;BR /&gt;
2014/07/09 - 11:10 AM &lt;BR /&gt;
2014/07/09 - 11:12 AM &lt;BR /&gt;
2014/07/09 - 11:33 AM &lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any idea if this is possible? If so, how? &lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229042#M44556</guid>
      <dc:creator>ofaura</dc:creator>
      <dc:date>2020-09-29T09:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk to set the event timestamp based on filename for date and events for time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229043#M44557</link>
      <description>&lt;P&gt;Below link should give you require details to understand how the timestamp recognition works in Splunk.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/HowSplunkextractstimestamps#How_Splunk_Enterprise_assigns_timestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/HowSplunkextractstimestamps#How_Splunk_Enterprise_assigns_timestamps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Basically you need the processing of point 4 from above link. An untested suggestion would to set the TIME_FORMAT to a value which is not present in the event and let Splunk identify the date from file name and time from event.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 16:58:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229043#M44557</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-05-02T16:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk to set the event timestamp based on filename for date and events for time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229044#M44558</link>
      <description>&lt;P&gt;Thanks for your answer, but it does not work. When I defined TIME_FORMAT to a value not present then Splunk applies the file mod date and time as the timestamp. &lt;/P&gt;

&lt;P&gt;So, I have been working on something like: &lt;/P&gt;

&lt;P&gt;TIME_FORMAT = %H%M%S%2N&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
BREAK_ONLY_BEFORE = ^\d{8}\s&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;/P&gt;

&lt;P&gt;And this works with the time, Splunk identify the time but not the date, and as you said, the documentations says: &lt;/P&gt;

&lt;P&gt;"4. If no events in a source have a date, Splunk Enterprise tries to find a date in the source name or file name. Time of day is not identified in filenames. (This requires that the events have a time, even though they don't have a date.) " &lt;/P&gt;

&lt;P&gt;So, this should be working but it does not, any suggestion? &lt;/P&gt;

&lt;P&gt;Thanks in advance, &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:39:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229044#M44558</guid>
      <dc:creator>ofaura</dc:creator>
      <dc:date>2020-09-29T09:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk to set the event timestamp based on filename for date and events for time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229045#M44559</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have found a workaround that it´s working fine. &lt;/P&gt;

&lt;P&gt;In props.conf: &lt;/P&gt;

&lt;P&gt;TIME_FORMAT = %H%M%S%2N&lt;BR /&gt;
DATETIME_CONFIG = &lt;BR /&gt;
TZ = Europe/Madrid&lt;/P&gt;

&lt;P&gt;And I have rename the file from LOG_14-07-09_1100.TST to  LOG_20140709_1100.TST and now, Splunk takes the date from the filename and time from the events. &lt;/P&gt;

&lt;P&gt;Oscar &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-to-set-the-event-timestamp-based-on/m-p/229045#M44559</guid>
      <dc:creator>ofaura</dc:creator>
      <dc:date>2020-09-29T09:39:59Z</dc:date>
    </item>
  </channel>
</rss>

