<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prepend all lines forwarded with a timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255312#M49039</link>
    <description>&lt;P&gt;It does NOT add it to the raw event but it causes the &lt;CODE&gt;_time&lt;/CODE&gt; field to have the value of the time when the event was indexed on the indexer (roughly the time the event was forwarded from the forwarder).&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2015 03:32:08 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-10-02T03:32:08Z</dc:date>
    <item>
      <title>Prepend all lines forwarded with a timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255309#M49036</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have an application log that doesn't contain timestamps, but we'd actually like to have them within the raw event.&lt;/P&gt;

&lt;P&gt;Is it possible (either on a Forwarder or at index time) to tell Splunk to prepend a timestamp to all lines it receives?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 16:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255309#M49036</guid>
      <dc:creator>Kindred</dc:creator>
      <dc:date>2015-10-01T16:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Prepend all lines forwarded with a timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255310#M49037</link>
      <description>&lt;P&gt;In your props.conf file put &lt;CODE&gt;DATETIME_CONFIG=CURRENT&lt;/CODE&gt; in the appropriate sourcetype stanza(s).&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 18:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255310#M49037</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-10-01T18:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Prepend all lines forwarded with a timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255311#M49038</link>
      <description>&lt;P&gt;This &lt;EM&gt;adds&lt;/EM&gt; a timestamp to the raw event?  I thought that was just related to ordering?  Will give it a try anyway and see.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 02:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255311#M49038</guid>
      <dc:creator>Kindred</dc:creator>
      <dc:date>2015-10-02T02:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Prepend all lines forwarded with a timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255312#M49039</link>
      <description>&lt;P&gt;It does NOT add it to the raw event but it causes the &lt;CODE&gt;_time&lt;/CODE&gt; field to have the value of the time when the event was indexed on the indexer (roughly the time the event was forwarded from the forwarder).&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 03:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255312#M49039</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-02T03:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Prepend all lines forwarded with a timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255313#M49040</link>
      <description>&lt;P&gt;This is not possible with just splunk; you will have to pre-process the events on the forwarder using some other software.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 03:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255313#M49040</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-02T03:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Prepend all lines forwarded with a timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255314#M49041</link>
      <description>&lt;P&gt;I thought as such since there are certain cases that would cause odd behaviour.  When the forwarder is reading the file in (relatively) real-time and they are getting indexed in a similar amount of time, then the added log timestamp would be useful to understand the order of the events when looking at the logs afterwards (outside of Splunk), but since you may have network issues and delays in forwarding/reading the file - if it indexed the entire file at once they'd all have the same timestamp which isn't that useful.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 05:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prepend-all-lines-forwarded-with-a-timestamp/m-p/255314#M49041</guid>
      <dc:creator>Kindred</dc:creator>
      <dc:date>2015-10-02T05:53:11Z</dc:date>
    </item>
  </channel>
</rss>

