<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to assign different timestamps based on log line contents within the same sourcetype? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298329#M56447</link>
    <description>&lt;P&gt;I am sending "pan:traffic" logs from our Palo Alto 3050 firewall to Splunk. I want the "_time" fields to be the same value as the "start_time" field when the log line contains "start" and use the time stamp that follows "PA-3050 1," when the log line contains "end"&lt;/P&gt;

&lt;P&gt;Is it possible to do different time stamps for events in the same source-type "pan:traffic" ?  I've bolded the time stamps I want to use for each in the samples below:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Sample start log line:&lt;/STRONG&gt;&lt;BR /&gt;
Feb 14 09:07:25 PA-3050 1,2017/02/14 09:07:25,001701007055,TRAFFIC,start,0,2017/02/14 09:07:25,10.0.0.1,77.000.000.88,0.0.0.0,0.0.0.0,User-to-Ext-Allow-DLP,domain\user,,web-browsing,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LF-LOG-ALLOW,2017/02/14 09:07:25,55537,1,58861,80,0,0,0x0,tcp,allow,740,678,62,4,&lt;STRONG&gt;2017/02/14 09:07:24&lt;/STRONG&gt;,0,any,0,442739216,0x0,10.0.0.0-10.255.255.255,US,0,3,1,n/a,0,0,0,0,,PA-3050,from-policy&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Sample end log line:&lt;/STRONG&gt;&lt;BR /&gt;
Feb 14 10:21:25 PA-3050 1,&lt;STRONG&gt;2017/02/14 10:21:24&lt;/STRONG&gt;,001701007055,TRAFFIC,end,0,2017/02/14 10:21:24,10.1.1.2,8.8.8.8,0.0.0.0,0.0.0.0,IntDC-to-ExtDNS,,,dns,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LF-LOG-ALLOW,2017/02/14 10:21:24,256848,1,50770,53,0,0,0x19,udp,allow,842,85,757,2,2017/02/14 10:20:52,30,any,0,443053418,0x0,10.0.0.0-10.255.255.255,US,0,1,1,aged-out,0,0,0,0,,PA-3050,from-policy&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:51:27 GMT</pubDate>
    <dc:creator>daishih</dc:creator>
    <dc:date>2020-09-29T12:51:27Z</dc:date>
    <item>
      <title>Is it possible to assign different timestamps based on log line contents within the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298329#M56447</link>
      <description>&lt;P&gt;I am sending "pan:traffic" logs from our Palo Alto 3050 firewall to Splunk. I want the "_time" fields to be the same value as the "start_time" field when the log line contains "start" and use the time stamp that follows "PA-3050 1," when the log line contains "end"&lt;/P&gt;

&lt;P&gt;Is it possible to do different time stamps for events in the same source-type "pan:traffic" ?  I've bolded the time stamps I want to use for each in the samples below:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Sample start log line:&lt;/STRONG&gt;&lt;BR /&gt;
Feb 14 09:07:25 PA-3050 1,2017/02/14 09:07:25,001701007055,TRAFFIC,start,0,2017/02/14 09:07:25,10.0.0.1,77.000.000.88,0.0.0.0,0.0.0.0,User-to-Ext-Allow-DLP,domain\user,,web-browsing,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LF-LOG-ALLOW,2017/02/14 09:07:25,55537,1,58861,80,0,0,0x0,tcp,allow,740,678,62,4,&lt;STRONG&gt;2017/02/14 09:07:24&lt;/STRONG&gt;,0,any,0,442739216,0x0,10.0.0.0-10.255.255.255,US,0,3,1,n/a,0,0,0,0,,PA-3050,from-policy&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Sample end log line:&lt;/STRONG&gt;&lt;BR /&gt;
Feb 14 10:21:25 PA-3050 1,&lt;STRONG&gt;2017/02/14 10:21:24&lt;/STRONG&gt;,001701007055,TRAFFIC,end,0,2017/02/14 10:21:24,10.1.1.2,8.8.8.8,0.0.0.0,0.0.0.0,IntDC-to-ExtDNS,,,dns,vsys1,trust,untrust,ethernet1/2,ethernet1/1,LF-LOG-ALLOW,2017/02/14 10:21:24,256848,1,50770,53,0,0,0x19,udp,allow,842,85,757,2,2017/02/14 10:20:52,30,any,0,443053418,0x0,10.0.0.0-10.255.255.255,US,0,1,1,aged-out,0,0,0,0,,PA-3050,from-policy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:51:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298329#M56447</guid>
      <dc:creator>daishih</dc:creator>
      <dc:date>2020-09-29T12:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to assign different timestamps based on log line contents within the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298330#M56448</link>
      <description>&lt;P&gt;Hi daishih,&lt;BR /&gt;
no: timestamp is unique for a sourcetype.&lt;/P&gt;

&lt;P&gt;Maybe you could a try but you have more license consuption:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;index all logs with the first sourcetype (so the first timestamp), &lt;/LI&gt;
&lt;LI&gt;extract the logs that you want with the second sourcetype (so the second timestamp) writing them in a file&lt;/LI&gt;
&lt;LI&gt;reindex the second one using the second sourcetype&lt;/LI&gt;
&lt;LI&gt;use a filer in your searches to exclude the extracted events from the first search&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I understand that is a pork-around, but I don't see anything else.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 16:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298330#M56448</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-02-14T16:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to assign different timestamps based on log line contents within the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298331#M56449</link>
      <description>&lt;P&gt;Give this a shot, should happen at index time (put on forwarders &amp;amp; indexers)&lt;/P&gt;

&lt;P&gt;Props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[pan:traffic]
TRANSFORMS-dateStartTimeTransform=dateStartTimeTransform
TRANSFORMS-dateEndTimeTransform=dateEndTimeTransform
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[dateStartTimeTransform]
SOURCE_KEY = _raw
REGEX = (?&amp;lt;=start).*(\d{4}\/\d{2}\/\d{2}\s\d{2}:\d{2}:\d{2})
DEST_KEY = _time

[dateEndTimeTransform]
SOURCE_KEY = _raw
REGEX = (\d{4}\/\d{2}\/\d{2}\s\d{2}:\d{2}:\d{2})(?=.*end)
DEST_KEY = _time
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 Feb 2017 16:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298331#M56449</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-02-14T16:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to assign different timestamps based on log line contents within the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298332#M56450</link>
      <description>&lt;P&gt;This works perfectly, thank you so much! It had never occurred to me to do a transform like that.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 16:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298332#M56450</guid>
      <dc:creator>daishih</dc:creator>
      <dc:date>2017-02-14T16:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to assign different timestamps based on log line contents within the same sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298333#M56451</link>
      <description>&lt;P&gt;Im actually surprised it works because the transforms.conf documentation says _time is time in epoch... but hey... if it works, it works!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 17:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-assign-different-timestamps-based-on-log-line/m-p/298333#M56451</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-02-14T17:01:45Z</dc:date>
    </item>
  </channel>
</rss>

