<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Eventgen Replay mode: all same timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440958#M76864</link>
    <description>&lt;P&gt;Hi, Please help me out.&lt;/P&gt;

&lt;P&gt;I try to generate events with replay mode, but it is not working properly. All timestamp is same. Of course original sample file is time series data, which means each event has different timestamp.&lt;/P&gt;

&lt;P&gt;[sampledata1.log]&lt;BR /&gt;
mode = replay&lt;BR /&gt;
outputMode = splunkstream&lt;BR /&gt;
token.0.token = \d{2}-\d{2}-\d{4} \d{2}:\d{2}:\d{2}.\d{3} token.0.replacementType = timestamp&lt;BR /&gt;
token.0.replacement = %m-%d-%Y %H:%M:%S.%f&lt;/P&gt;

&lt;P&gt;sampledata1.log&lt;BR /&gt;
"08-07-2019 22:00:03.595 +0900 INFO  loader - Running utility: ""validatedb"""&lt;BR /&gt;
"08-07-2019 22:00:04.496 +0900 INFO  loader - Getting configuration data from: /home/splunk/etc/myinstall/splunkd.xml"&lt;BR /&gt;
"08-07-2019 22:00:05.586 +0900 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to /home/splunk/etc/modules"&lt;BR /&gt;
"08-07-2019 22:00:06.596 +0900 INFO  loader - loading modules from /home/splunk/etc/modules"&lt;BR /&gt;
"08-07-2019 22:00:07.597 +0900 INFO  loader - Writing out composite configuration file: /home/splunk/var/run/splunk/composite.xml"&lt;BR /&gt;
................&lt;/P&gt;

&lt;P&gt;After restart splunk, I could see this view. Generated events have same timestamp.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/273415-screen-shot-2019-08-09-at-45733-am.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;What I have to do? What wrong with this?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:41:59 GMT</pubDate>
    <dc:creator>brandy81</dc:creator>
    <dc:date>2020-09-30T01:41:59Z</dc:date>
    <item>
      <title>Eventgen Replay mode: all same timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440958#M76864</link>
      <description>&lt;P&gt;Hi, Please help me out.&lt;/P&gt;

&lt;P&gt;I try to generate events with replay mode, but it is not working properly. All timestamp is same. Of course original sample file is time series data, which means each event has different timestamp.&lt;/P&gt;

&lt;P&gt;[sampledata1.log]&lt;BR /&gt;
mode = replay&lt;BR /&gt;
outputMode = splunkstream&lt;BR /&gt;
token.0.token = \d{2}-\d{2}-\d{4} \d{2}:\d{2}:\d{2}.\d{3} token.0.replacementType = timestamp&lt;BR /&gt;
token.0.replacement = %m-%d-%Y %H:%M:%S.%f&lt;/P&gt;

&lt;P&gt;sampledata1.log&lt;BR /&gt;
"08-07-2019 22:00:03.595 +0900 INFO  loader - Running utility: ""validatedb"""&lt;BR /&gt;
"08-07-2019 22:00:04.496 +0900 INFO  loader - Getting configuration data from: /home/splunk/etc/myinstall/splunkd.xml"&lt;BR /&gt;
"08-07-2019 22:00:05.586 +0900 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to /home/splunk/etc/modules"&lt;BR /&gt;
"08-07-2019 22:00:06.596 +0900 INFO  loader - loading modules from /home/splunk/etc/modules"&lt;BR /&gt;
"08-07-2019 22:00:07.597 +0900 INFO  loader - Writing out composite configuration file: /home/splunk/var/run/splunk/composite.xml"&lt;BR /&gt;
................&lt;/P&gt;

&lt;P&gt;After restart splunk, I could see this view. Generated events have same timestamp.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/273415-screen-shot-2019-08-09-at-45733-am.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;What I have to do? What wrong with this?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440958#M76864</guid>
      <dc:creator>brandy81</dc:creator>
      <dc:date>2020-09-30T01:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen Replay mode: all same timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440959#M76865</link>
      <description>&lt;P&gt;It must be extracting timestamp issue. But It's correct! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Could anyone please let me know what's wrong?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7487i673C537CC3E68F27/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 03:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440959#M76865</guid>
      <dc:creator>brandy81</dc:creator>
      <dc:date>2019-08-09T03:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen Replay mode: all same timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440960#M76866</link>
      <description>&lt;P&gt;You are using the following line:&lt;BR /&gt;
token.0.replacementType = timestamp&lt;BR /&gt;
Instead you should use:&lt;BR /&gt;
token.0.replacementType = replaytimestamp&lt;/P&gt;

&lt;P&gt;This should fix your problem.&lt;/P&gt;

&lt;P&gt;Tip: The replaytimestamp is based on the difference of the timestamps in your sample file. So you might want to increase the difference in your sample.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 13:09:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440960#M76866</guid>
      <dc:creator>dpeukert</dc:creator>
      <dc:date>2019-08-09T13:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen Replay mode: all same timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440961#M76867</link>
      <description>&lt;P&gt;Thank you for the answer. But I don't understand these combination below:&lt;BR /&gt;
1. mode=reply / token.x.replacementType = replaytimestamp&lt;BR /&gt;
2. mode=reply / token.x.replacementType = timestamp&lt;BR /&gt;
3. mode=sample / token.x.replacementType = replaytimestamp&lt;BR /&gt;
4. mode=sample / token.x.replacementType = timestamp&lt;/P&gt;

&lt;P&gt;I tested 4 cases and got to know what' differences between them, but, I would like to get to know about each option based on cases. Could anybody please let me know about those cases?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2019 07:51:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Eventgen-Replay-mode-all-same-timestamp/m-p/440961#M76867</guid>
      <dc:creator>brandy81</dc:creator>
      <dc:date>2019-08-11T07:51:30Z</dc:date>
    </item>
  </channel>
</rss>

