<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk not picking up datetime in the following logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439632#M76642</link>
    <description>&lt;P&gt;No Specific Reason I am just doing testing and playing with the data was not aware of MAX_DAYS_AGo Setting &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:25:34 GMT</pubDate>
    <dc:creator>vikas_gopal</dc:creator>
    <dc:date>2020-09-29T22:25:34Z</dc:date>
    <item>
      <title>Why is Splunk not picking up datetime in the following logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439628#M76638</link>
      <description>&lt;P&gt;![alt text][1]HI Experts,&lt;/P&gt;

&lt;P&gt;I have the following 2 logs. Why 2? Because I know BREAK_ONLY_BEFORE = Path=&lt;/P&gt;

&lt;P&gt;I want the timestamp: "2006-09-21, 02:57:11.58"&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{{"2006-09-21, 02:57:11.58", 122, 11, "Path=/LoginUser Query=CrmId=ClientABC&amp;amp;ContentItemId=TotalAccess&amp;amp;SessionId=3A1785URH117BEA&amp;amp;Ticket=646A1DA4STF896EE&amp;amp;SessionTime=25368&amp;amp;ReturnUrl=http://www.clientabc.com, Method=GET, IP=209.51.249.195, Content=", ""}} 
{{"2006-09-21, 02:57:11.60", 122, 15, "UserData:&amp;lt;User CrmId="clientabc" UserId="p12345678"&amp;gt;&amp;lt;EntitlementList&amp;gt;&amp;lt;/EntitlementList&amp;gt;&amp;lt;/User&amp;gt;", ""}} 
{{"2006-09-21, 02:57:11.60", 122, 15, "New Cookie: SessionId=3A1785URH117BEA&amp;amp;Ticket=646A1DA4STF896EE&amp;amp;CrmId=clientabc&amp;amp;UserId=p12345678&amp;amp;AccountId=&amp;amp;AgentHost=man&amp;amp;AgentId=man, MANUser: Version=1&amp;amp;Name=&amp;amp;Debit=&amp;amp;Credit=&amp;amp;AccessTime=&amp;amp;BillDay=&amp;amp;Status=&amp;amp;Language=&amp;amp;Country=&amp;amp;Email=&amp;amp;EmailNotify=&amp;amp;Pin=&amp;amp;PinPayment=&amp;amp;PinAmount=&amp;amp;PinPG=&amp;amp;PinPGRate=&amp;amp;PinMenu=&amp;amp;", ""}}
{{"2006-09-21, 02:57:11.58", 122, 11, "Path=/LoginUser Query=CrmId=ClientABC&amp;amp;ContentItemId=TotalAccess&amp;amp;SessionId=3A1785URH117BEA&amp;amp;Ticket=646A1DA4STF896EE&amp;amp;SessionTime=25368&amp;amp;ReturnUrl=http://www.clientabc.com, Method=GET, IP=209.51.249.195, Content=", ""}} 
{{"2006-09-21, 02:57:11.60", 122, 15, "UserData:&amp;lt;User CrmId="clientabc" UserId="p12345678"&amp;gt;&amp;lt;EntitlementList&amp;gt;&amp;lt;/EntitlementList&amp;gt;&amp;lt;/User&amp;gt;", ""}} 
{{"2006-09-21, 02:57:11.60", 122, 15, "New Cookie: SessionId=3A1785URH117BEA&amp;amp;Ticket=646A1DA4STF896EE&amp;amp;CrmId=clientabc&amp;amp;UserId=p12345678&amp;amp;AccountId=&amp;amp;AgentHost=man&amp;amp;AgentId=man, MANUser: Version=1&amp;amp;Name=&amp;amp;Debit=&amp;amp;Credit=&amp;amp;AccessTime=&amp;amp;BillDay=&amp;amp;Status=&amp;amp;Language=&amp;amp;Country=&amp;amp;Email=&amp;amp;EmailNotify=&amp;amp;Pin=&amp;amp;PinPayment=&amp;amp;PinAmount=&amp;amp;PinPG=&amp;amp;PinPGRate=&amp;amp;PinMenu=&amp;amp;", ""}}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have the below settings at source type selection in preview mode &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ test123 ]
SHOULD_LINEMERGE=true
NO_BINARY_CHECK=true
BREAK_ONLY_BEFORE=Path=
CHARSET=AUTO
MAX_TIMESTAMP_LOOKAHEAD=30][1]
TIME_FORMAT= %Y-%m-%d, %H:%M:%S
TIME_PREFIX={{"
category=Custom
disabled=false
pulldown_type=true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;With the above settings, I am getting the below error as shown in the snippet.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://answers.splunk.com/storage/attachments/262589-splunk-sourcetype-error.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439628#M76638</guid>
      <dc:creator>vikas_gopal</dc:creator>
      <dc:date>2020-09-29T22:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not picking up datetime in the following logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439629#M76639</link>
      <description>&lt;P&gt;is there any particular reason why you want to merge 3 lines of raw data into 1 rather than breaking them into 3 separate events, as you get a significant boost to processing speed when you use LINE_BREAKER to delimit multi-line events as opposed to using SHOULD_LINEMERGE to reassemble individual lines into multi-line events.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439629#M76639</guid>
      <dc:creator>soumyasaha25</dc:creator>
      <dc:date>2020-09-29T22:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not picking up datetime in the following logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439630#M76640</link>
      <description>&lt;P&gt;The error message is pretty much self-explanatory. Splunk does not want to index data which is too old. You events are from 2006.&lt;/P&gt;

&lt;P&gt;According to &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf" target="_blank"&gt;props.conf&lt;/A&gt; regarding &lt;STRONG&gt;MAX_DAYS_AGO&lt;/STRONG&gt;:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Defaults to 2000 (days), maximum 10951.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So set MAX_DAYS_AGO=10000 and you should be fine if you really want to index this old data.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:25:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439630#M76640</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2020-09-29T22:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not picking up datetime in the following logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439631#M76641</link>
      <description>&lt;P&gt;Ahaaa!!! worked like a charm Thank you so much&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 12:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439631#M76641</guid>
      <dc:creator>vikas_gopal</dc:creator>
      <dc:date>2018-12-18T12:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not picking up datetime in the following logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439632#M76642</link>
      <description>&lt;P&gt;No Specific Reason I am just doing testing and playing with the data was not aware of MAX_DAYS_AGo Setting &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-picking-up-datetime-in-the-following-logs/m-p/439632#M76642</guid>
      <dc:creator>vikas_gopal</dc:creator>
      <dc:date>2020-09-29T22:25:34Z</dc:date>
    </item>
  </channel>
</rss>

