<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DATETIME_CONFIG=NONE DateParserVerbose - Failed to parse timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271982#M52256</link>
    <description>&lt;P&gt;Hi Cusello, I have tab delimited file with 1000 lines and I do not want Splunk to read time from logs. DATTIME_CONFIG is set to&lt;BR /&gt;&lt;BR /&gt;
NONE so that it can take file modified timestamp of file in Linux. WIth SHOULD_LINEMERGE set of false, my understanding it that all 1000 lines be converted to 1000 events with file modified timestamp as _time&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:41:36 GMT</pubDate>
    <dc:creator>chillao123</dc:creator>
    <dc:date>2020-09-29T12:41:36Z</dc:date>
    <item>
      <title>DATETIME_CONFIG=NONE DateParserVerbose - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271980#M52254</link>
      <description>&lt;P&gt;Hi, I am facing weird issue with timestamp recognition by splunk. Modified timestamp is 2016/11/26 but somehow I see 1998 in splunkd log. File is not getting indexed due to these errors. &lt;/P&gt;

&lt;P&gt;Performed the following actions:&lt;/P&gt;

&lt;P&gt;Set DATETIME_CONFIG=NONE in forwarder props and indexer props conf file. But I see the following errors:&lt;/P&gt;

&lt;P&gt;01-31-2017 19:32:37.365 -0700 WARN  DateParserVerbose - A possible timestamp match (Sun Dec 20 20:15:49 1998) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source::/tmp/BT99P.BBMXDC48.EXTRACT_161129235057_0643&lt;/P&gt;

&lt;P&gt;01-31-2017 19:32:21.236 -0700 WARN  DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Thu Jan 30 06:07:54 2014). Context: source::/tmp/BT99P.BBMXDC48.EXTRACT_161129235057_0643&lt;/P&gt;

&lt;P&gt;Copying below btool output:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Forwarder:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;23242 [test_abcd]&lt;BR /&gt;
23243 ANNOTATE_PUNCT = True&lt;BR /&gt;
23244 AUTO_KV_JSON = true&lt;BR /&gt;
23245 BREAK_ONLY_BEFORE =&lt;BR /&gt;
23246 BREAK_ONLY_BEFORE_DATE = false&lt;BR /&gt;
23247 CHARSET = UTF-8&lt;BR /&gt;
23248 DATETIME_CONFIG = NONE&lt;BR /&gt;
23249 HEADER_MODE =&lt;BR /&gt;
23250 LEARN_SOURCETYPE = true&lt;BR /&gt;
23251 LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
23252 MAX_DAYS_AGO = 2000&lt;BR /&gt;
23253 MAX_DAYS_HENCE = 2&lt;BR /&gt;
23254 MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
23255 MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
23256 MAX_EVENTS = 256&lt;BR /&gt;
23257 MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
23258 MUST_BREAK_AFTER =&lt;BR /&gt;
23259 MUST_NOT_BREAK_AFTER =&lt;BR /&gt;
23260 MUST_NOT_BREAK_BEFORE =&lt;BR /&gt;
23261 NO_BINARY_CHECK = true&lt;BR /&gt;
23262 SEGMENTATION = indexing&lt;BR /&gt;
23263 SEGMENTATION-all = full&lt;BR /&gt;
23264 SEGMENTATION-inner = inner&lt;BR /&gt;
23265 SEGMENTATION-outer = outer&lt;BR /&gt;
23266 SEGMENTATION-raw = none&lt;BR /&gt;
23267 SEGMENTATION-standard = standard&lt;BR /&gt;
23268 SHOULD_LINEMERGE = false&lt;BR /&gt;
23269 TRANSFORMS =&lt;BR /&gt;
23270 TRUNCATE = 10000&lt;BR /&gt;
23271 detect_trailing_nulls = false&lt;BR /&gt;
23272 disabled = false&lt;BR /&gt;
23273 maxDist = 100&lt;BR /&gt;
23274 priority =&lt;BR /&gt;
23275 pulldown_type = true&lt;BR /&gt;
23276 sourcetype =&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Indexer props:&lt;/STRONG&gt;&lt;BR /&gt;
 8891 [test_abcd]&lt;BR /&gt;
 8892 ANNOTATE_PUNCT = True&lt;BR /&gt;
 8893 AUTO_KV_JSON = true&lt;BR /&gt;
 8894 BREAK_ONLY_BEFORE =&lt;BR /&gt;
 8895 BREAK_ONLY_BEFORE_DATE = false&lt;BR /&gt;
 8896 CHARSET = UTF-8&lt;BR /&gt;
 8897 DATETIME_CONFIG = NONE&lt;BR /&gt;
 8898 HEADER_MODE =&lt;BR /&gt;
 8899 LEARN_SOURCETYPE = true&lt;BR /&gt;
 8900 LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
 8901 MAX_DAYS_AGO = 2000&lt;BR /&gt;
 8902 MAX_DAYS_HENCE = 2&lt;BR /&gt;
 8903 MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
 8904 MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
 8905 MAX_EVENTS = 256&lt;BR /&gt;
 8906 MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
 8907 MUST_BREAK_AFTER =&lt;BR /&gt;
 8908 MUST_NOT_BREAK_AFTER =&lt;BR /&gt;
 8909 MUST_NOT_BREAK_BEFORE =&lt;BR /&gt;
 8910 NO_BINARY_CHECK = true&lt;BR /&gt;
 8911 SEGMENTATION = indexing&lt;BR /&gt;
 8912 SEGMENTATION-all = full&lt;BR /&gt;
 8913 SEGMENTATION-inner = inner&lt;BR /&gt;
 8914 SEGMENTATION-outer = outer&lt;BR /&gt;
 8915 SEGMENTATION-raw = none&lt;BR /&gt;
 8916 SEGMENTATION-standard = standard&lt;BR /&gt;
 8917 SHOULD_LINEMERGE = false&lt;BR /&gt;
 8918 TRANSFORMS =&lt;BR /&gt;
 8919 TRUNCATE = 10000&lt;BR /&gt;
 8920 detect_trailing_nulls = false&lt;BR /&gt;
 8921 disabled = false&lt;BR /&gt;
 8922 maxDist = 100&lt;BR /&gt;
 8923 priority =&lt;BR /&gt;
 8924 pulldown_type = true&lt;/P&gt;

&lt;P&gt;On OS linux file's timestamp:&lt;/P&gt;

&lt;P&gt;File: `BT99P.BBMXDC48.EXTRACT_161129235057_0643'&lt;BR /&gt;
  Size: 18012132        Blocks: 35184      IO Block: 4096   regular file&lt;BR /&gt;
Device: fd03h/64771d    Inode: 524302      Links: 1&lt;BR /&gt;
Access: (0755/-rwxr-xr-x)  Uid: (617339/#####)   Gid: (6000000/users)&lt;BR /&gt;
Access: 2017-01-31 19:31:49.335197997 -0700&lt;BR /&gt;
&lt;STRONG&gt;Modify: 2016-11-26 00:00:09.000000000 -0700&lt;/STRONG&gt;&lt;BR /&gt;
Change: 2017-01-31 19:14:56.740167230 -0700&lt;/P&gt;

&lt;P&gt;Need to load old file with modified timestamp as 2016/11/26. Please advise settings need to be made.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271980#M52254</guid>
      <dc:creator>chillao123</dc:creator>
      <dc:date>2020-09-29T12:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG=NONE DateParserVerbose - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271981#M52255</link>
      <description>&lt;P&gt;Hi chillao123,&lt;BR /&gt;
I don't see in tour props.conf the TIME_FORMAT option that is responsable of the correct timestamp reading.&lt;BR /&gt;
If you want anhelp to build this option, Could you share an example of your logs?&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 08:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271981#M52255</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-02-01T08:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG=NONE DateParserVerbose - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271982#M52256</link>
      <description>&lt;P&gt;Hi Cusello, I have tab delimited file with 1000 lines and I do not want Splunk to read time from logs. DATTIME_CONFIG is set to&lt;BR /&gt;&lt;BR /&gt;
NONE so that it can take file modified timestamp of file in Linux. WIth SHOULD_LINEMERGE set of false, my understanding it that all 1000 lines be converted to 1000 events with file modified timestamp as _time&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:41:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271982#M52256</guid>
      <dc:creator>chillao123</dc:creator>
      <dc:date>2020-09-29T12:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG=NONE DateParserVerbose - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271983#M52257</link>
      <description>&lt;P&gt;Hi @cussello,&lt;BR /&gt;
PFB the sample log:&lt;BR /&gt;
002     T*****  DEBITS          AIR     17/11/16        XXXXX878*&lt;EM&gt;91XX2 XX9987&lt;/EM&gt;**&lt;EM&gt;**5280        322555521528000         3704.00 LA4667A 2016-11-25      *&lt;/EM&gt;&lt;EM&gt;072&lt;/EM&gt;&lt;EM&gt;98              Q&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt;DO RI&lt;/EM&gt;&lt;/STRONG&gt;A/PA**                             B*&lt;EM&gt;A **NCO&lt;/EM&gt;** AS                     110015005       IN-&lt;STRONG&gt;U&lt;/STRONG&gt; TE**** DIR GARL* DIST  AM07    GLX *&lt;STRONG&gt;&lt;EM&gt;RAL XEM                 0008                                    004200&lt;/EM&gt;&lt;/STRONG&gt;                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 66&lt;BR /&gt;
002     T*****  DEBITS          AIR     24/11/16        XXXXX878*&lt;STRONG&gt;1XX2 4O&lt;/STRONG&gt;&lt;STRONG&gt;3281&lt;/STRONG&gt;&lt;STRONG&gt;25        329555583602000         2903.00 LA4667A 2016-11-25      ***072&lt;/STRONG&gt;98              R*&lt;EM&gt;IR&lt;/EM&gt;* &lt;STRONG&gt;RNAN&lt;/STRONG&gt;&lt;EM&gt;/MA                            B&lt;/EM&gt;&lt;EM&gt;A **NCO&lt;/EM&gt;** AS                     110015005       IN-&lt;STRONG&gt;U&lt;/STRONG&gt; TE**** DIR GARL* DIST  AM07    GLX *&lt;STRONG&gt;&lt;EM&gt;RAL XEM                 0001                                    0042&lt;/EM&gt;&lt;/STRONG&gt;33    &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271983#M52257</guid>
      <dc:creator>inderjot_rasila</dc:creator>
      <dc:date>2020-09-29T12:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: DATETIME_CONFIG=NONE DateParserVerbose - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271984#M52258</link>
      <description>&lt;P&gt;I agree that your configurations look acceptable but check out this Q&amp;amp;A:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/455406/why-am-i-getting-dateparserverbose-warnings-althou.html"&gt;https://answers.splunk.com/answers/455406/why-am-i-getting-dateparserverbose-warnings-althou.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;According to that, you need to remove the &lt;CODE&gt;DATETIME_CONFIG=NONE&lt;/CODE&gt; from your indexers, which is exactly what I would try.  If this fixes it, though, this really should be reported as a bug because it means that a setting that should AT MOST cause the Indexers NOT to do any timestamping, actually turns this back on.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 22:33:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DATETIME-CONFIG-NONE-DateParserVerbose-Failed-to-parse-timestamp/m-p/271984#M52258</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-02T22:33:29Z</dc:date>
    </item>
  </channel>
</rss>

