<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Datetime.xml not working for log with multiple timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Custom-Datetime-xml-not-working-for-log-with-multiple-timestamp/m-p/306097#M57735</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have log which have 5 different timestamp. I am trying to use custom datetime.xml created using splunk train dates cmd but it is not working.&lt;/P&gt;

&lt;P&gt;Different Timestamps&lt;/P&gt;

&lt;P&gt;2018-01-05_18:15:42.208&lt;BR /&gt;
2018-01-05 18:15:42&lt;BR /&gt;
Jan 5, 2018 6:15:52 PM&lt;BR /&gt;
&amp;lt;05-Jan-2018 6:15:58,916 EST PM&amp;gt;&lt;/P&gt;

&lt;P&gt;custom datetime.xml&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;lt;(\w+)\s(\d+),\s(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[,\s\d+\s(\d+):(\d+):(\d+)\s(\w+)\s(\w+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[(\d+)-(\d+)-(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[-\d+-\d+_(\d+):(\d+):(\d+)\.(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;



    &amp;lt;text&amp;gt;&amp;lt;![CDATA[(\d+)-(\d+)-(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[-\d+-\d+\s(\d+):(\d+):(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;



    &amp;lt;text&amp;gt;&amp;lt;![CDATA[(\w+)\s(\d+),\s(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[,\s\d+\s(\d+):(\d+):(\d+)\s(\w+)]]&amp;gt;&amp;lt;/text&amp;gt;



    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;lt;(\d+)-(\w+)-(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\w-\d+\s(\d+):(\d+):(\d+),\d+\s(\w+)\s(\w+)]]&amp;gt;&amp;lt;/text&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
TZ_ALIAS=EST=GMT+11&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
NO_BINARY_CHECK=true&lt;BR /&gt;
CHARSET=UTF-8&lt;BR /&gt;
disabled=false&lt;BR /&gt;
DATETIME_CONFIG = /opt/splunk/etc/system/local/datetime.xml&lt;BR /&gt;
LINE_BREAKER=([\r\n]+)(?:(?:&amp;lt;(\w{3})\s(\d{1,2}),\s(\d{4})\s(\d{1,2}):(\d{2}):(\d{2})\s(\w{2})\s(\w{3})&amp;gt;)|(?:(\d{4})-(\d{2})-(\d{2})_(\d{2}):(\d{2}):(\d{2}).(\d{3}))|(?:(\d{4})-(\d{2})-(\d{2})\s(\d{2}):(\d{2}):(\d{2}))|(?:(\w{3})\s(\d{1,2}),\s(\d{4})\s(\d{1,2}):(\d{2}):(\d{2})\s(\w{2}))|(?:&amp;lt;(\d{1,2})-(\w{3})-(\d{4})\s(\d{1,2}):(\d{2}):(\d{2}),(\d{3})\s(\w{3})\s(\w{2})&amp;gt;))&lt;/P&gt;

&lt;P&gt;When testing using above configuration using Add Data - Splunk is not showing any data and reporting "No results found. Please change source type, adjust source type settings, or check your source file."&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:39:15 GMT</pubDate>
    <dc:creator>hemendralodhi</dc:creator>
    <dc:date>2020-09-29T17:39:15Z</dc:date>
    <item>
      <title>Custom Datetime.xml not working for log with multiple timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-Datetime-xml-not-working-for-log-with-multiple-timestamp/m-p/306097#M57735</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have log which have 5 different timestamp. I am trying to use custom datetime.xml created using splunk train dates cmd but it is not working.&lt;/P&gt;

&lt;P&gt;Different Timestamps&lt;/P&gt;

&lt;P&gt;2018-01-05_18:15:42.208&lt;BR /&gt;
2018-01-05 18:15:42&lt;BR /&gt;
Jan 5, 2018 6:15:52 PM&lt;BR /&gt;
&amp;lt;05-Jan-2018 6:15:58,916 EST PM&amp;gt;&lt;/P&gt;

&lt;P&gt;custom datetime.xml&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;lt;(\w+)\s(\d+),\s(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[,\s\d+\s(\d+):(\d+):(\d+)\s(\w+)\s(\w+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[(\d+)-(\d+)-(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[-\d+-\d+_(\d+):(\d+):(\d+)\.(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;



    &amp;lt;text&amp;gt;&amp;lt;![CDATA[(\d+)-(\d+)-(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[-\d+-\d+\s(\d+):(\d+):(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;



    &amp;lt;text&amp;gt;&amp;lt;![CDATA[(\w+)\s(\d+),\s(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[,\s\d+\s(\d+):(\d+):(\d+)\s(\w+)]]&amp;gt;&amp;lt;/text&amp;gt;



    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\&amp;lt;(\d+)-(\w+)-(\d+)]]&amp;gt;&amp;lt;/text&amp;gt;


    &amp;lt;text&amp;gt;&amp;lt;![CDATA[\w-\d+\s(\d+):(\d+):(\d+),\d+\s(\w+)\s(\w+)]]&amp;gt;&amp;lt;/text&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
TZ_ALIAS=EST=GMT+11&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
NO_BINARY_CHECK=true&lt;BR /&gt;
CHARSET=UTF-8&lt;BR /&gt;
disabled=false&lt;BR /&gt;
DATETIME_CONFIG = /opt/splunk/etc/system/local/datetime.xml&lt;BR /&gt;
LINE_BREAKER=([\r\n]+)(?:(?:&amp;lt;(\w{3})\s(\d{1,2}),\s(\d{4})\s(\d{1,2}):(\d{2}):(\d{2})\s(\w{2})\s(\w{3})&amp;gt;)|(?:(\d{4})-(\d{2})-(\d{2})_(\d{2}):(\d{2}):(\d{2}).(\d{3}))|(?:(\d{4})-(\d{2})-(\d{2})\s(\d{2}):(\d{2}):(\d{2}))|(?:(\w{3})\s(\d{1,2}),\s(\d{4})\s(\d{1,2}):(\d{2}):(\d{2})\s(\w{2}))|(?:&amp;lt;(\d{1,2})-(\w{3})-(\d{4})\s(\d{1,2}):(\d{2}):(\d{2}),(\d{3})\s(\w{3})\s(\w{2})&amp;gt;))&lt;/P&gt;

&lt;P&gt;When testing using above configuration using Add Data - Splunk is not showing any data and reporting "No results found. Please change source type, adjust source type settings, or check your source file."&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:39:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-Datetime-xml-not-working-for-log-with-multiple-timestamp/m-p/306097#M57735</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2020-09-29T17:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Datetime.xml not working for log with multiple timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-Datetime-xml-not-working-for-log-with-multiple-timestamp/m-p/306098#M57736</link>
      <description>&lt;P&gt;Here is the configuration for datetime.xml&lt;BR /&gt;
&lt;A href="https://answers.splunk.comstorage/temp/225725-datetime-xml.txt"&gt;datetime.xml&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2018 07:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-Datetime-xml-not-working-for-log-with-multiple-timestamp/m-p/306098#M57736</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2018-01-15T07:12:04Z</dc:date>
    </item>
  </channel>
</rss>

