<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to configure timestamp extraction in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-configure-timestamp-extraction/m-p/32384#M5757</link>
    <description>&lt;P&gt;Am trying to index log entries there the time stamp information is at the starting of the first line of each log entry.&lt;BR /&gt;
Sample timestamps from entries in a couple of types of associated log files are: &lt;BR /&gt;
[7/17/10 4:24:53:269 CST] 00000048 SystemErr . . . &lt;BR /&gt;
[10/5/11 11:55:08:992 PDT] 00000029 SystemOut . . . &lt;BR /&gt;
[11/30/11 8:09:06:400 PST] 0000006e SystemOut . . . &lt;BR /&gt;
[12/9/11 0:52:10:743 PST] 0000000a ResourceMgrIm . . . &lt;BR /&gt;
2/17/10 02:38:11 AM CST [INFO] [...Agent] . . .&lt;BR /&gt;
10/28/10 08:29:01 PM CDT [ERROR] [...Agent.Properties] . . .&lt;BR /&gt;
12/09/10 10:08:33 PM CST [WARN] [...Agent] . . .&lt;BR /&gt;
11/30/11 08:11:08 PM PST [INFO] [...Agent] . . . &lt;/P&gt;

&lt;P&gt;This is obviously ambiguous in form for date ( since 11/9/10 fould be year 2010 or 2011.&lt;BR /&gt;
Have tried the following but doesn't work with recent entries at least those form of 1st 4 from today.   Splunk doesnt recognize the time stamp.  Am suspecting an issue with the day portion since only a single digit.  Can't seem to find if there is  a day designator form that allows for a single digit.&lt;/P&gt;

&lt;P&gt;In Applications's props.conf file:&lt;BR /&gt;
[host::sample]&lt;BR /&gt;
TIME_PREFIX = ^.&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 22&lt;BR /&gt;
TIME_FORMAT = %y/%d/%m %k%M%S&lt;/P&gt;

&lt;P&gt;Anyone have some good suggestions? &lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 10:12:46 GMT</pubDate>
    <dc:creator>clmiller</dc:creator>
    <dc:date>2020-09-28T10:12:46Z</dc:date>
    <item>
      <title>Trying to configure timestamp extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-configure-timestamp-extraction/m-p/32384#M5757</link>
      <description>&lt;P&gt;Am trying to index log entries there the time stamp information is at the starting of the first line of each log entry.&lt;BR /&gt;
Sample timestamps from entries in a couple of types of associated log files are: &lt;BR /&gt;
[7/17/10 4:24:53:269 CST] 00000048 SystemErr . . . &lt;BR /&gt;
[10/5/11 11:55:08:992 PDT] 00000029 SystemOut . . . &lt;BR /&gt;
[11/30/11 8:09:06:400 PST] 0000006e SystemOut . . . &lt;BR /&gt;
[12/9/11 0:52:10:743 PST] 0000000a ResourceMgrIm . . . &lt;BR /&gt;
2/17/10 02:38:11 AM CST [INFO] [...Agent] . . .&lt;BR /&gt;
10/28/10 08:29:01 PM CDT [ERROR] [...Agent.Properties] . . .&lt;BR /&gt;
12/09/10 10:08:33 PM CST [WARN] [...Agent] . . .&lt;BR /&gt;
11/30/11 08:11:08 PM PST [INFO] [...Agent] . . . &lt;/P&gt;

&lt;P&gt;This is obviously ambiguous in form for date ( since 11/9/10 fould be year 2010 or 2011.&lt;BR /&gt;
Have tried the following but doesn't work with recent entries at least those form of 1st 4 from today.   Splunk doesnt recognize the time stamp.  Am suspecting an issue with the day portion since only a single digit.  Can't seem to find if there is  a day designator form that allows for a single digit.&lt;/P&gt;

&lt;P&gt;In Applications's props.conf file:&lt;BR /&gt;
[host::sample]&lt;BR /&gt;
TIME_PREFIX = ^.&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 22&lt;BR /&gt;
TIME_FORMAT = %y/%d/%m %k%M%S&lt;/P&gt;

&lt;P&gt;Anyone have some good suggestions? &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-configure-timestamp-extraction/m-p/32384#M5757</guid>
      <dc:creator>clmiller</dc:creator>
      <dc:date>2020-09-28T10:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to configure timestamp extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-configure-timestamp-extraction/m-p/32385#M5758</link>
      <description>&lt;P&gt;See my answer to a similar question&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/36207/how-do-i-configure-timestamp-extraction-where-day-may-be-one-or-two-digits"&gt;http://splunk-base.splunk.com/answers/36207/how-do-i-configure-timestamp-extraction-where-day-may-be-one-or-two-digits&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;hth,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2011 11:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-configure-timestamp-extraction/m-p/32385#M5758</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-12-15T11:50:48Z</dc:date>
    </item>
  </channel>
</rss>

