<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Props.conf Timestamp Not Parsing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455148#M78732</link>
    <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = \[
TIME_FORMAT = %m/%d/%y %H:%M:%S:%3N %Z
MAX_TIMESTAMP_LOOKAHEAD = 25
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Deploy to the first full instance of Splunk that handles the events (HF or Indexers), restart all splunk instances there, send in new events and only check those (old events will stay broken); use &lt;CODE&gt;_index_earliest=-5m&lt;/CODE&gt; to be sure that you are looking at newly-indexed events.&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 17:43:33 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-05-14T17:43:33Z</dc:date>
    <item>
      <title>Props.conf Timestamp Not Parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455146#M78730</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have events that are being indexed with "index time" timestamps and would like to use the timestamp from the event itself. When i upload the logs to our standalone host, splunk recognizes the timestamps from the logs and present us with the following fields for that sourcetype. (see below) However, when we deploy this to our indexers and resttart the service, events come in with the what appears to be index time timestamps. For some reason, splunk isnt recognizing the milliseconds portion of the event.&lt;/P&gt;

&lt;P&gt;Thoughts?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/272716-timestamps.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;[sourcetype-a]&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
TIME_PREFIX = [&lt;BR /&gt;
TIME_FORMAT = %m/%d/%y %H:%M:%S:%N %Z&lt;BR /&gt;
BREAK_ONLY_BEFORE = ^[\d{1,2}/\d{1,2}/\d{1,2}\s+\d{1,2}:\d{1,2}:\d{1,2}&lt;BR /&gt;
MAX_EVENTS = 10000&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455146#M78730</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2020-09-30T00:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf Timestamp Not Parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455147#M78731</link>
      <description>&lt;P&gt;Try using %3N&lt;/P&gt;

&lt;P&gt;"For GNU date-time nanoseconds. Specify any sub-second parsing by providing the width: %3N = milliseconds, %6N = microseconds, %9N = nanoseconds."&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Configuretimestamprecognition"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 17:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455147#M78731</guid>
      <dc:creator>shawnab</dc:creator>
      <dc:date>2019-05-14T17:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Props.conf Timestamp Not Parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455148#M78732</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = \[
TIME_FORMAT = %m/%d/%y %H:%M:%S:%3N %Z
MAX_TIMESTAMP_LOOKAHEAD = 25
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Deploy to the first full instance of Splunk that handles the events (HF or Indexers), restart all splunk instances there, send in new events and only check those (old events will stay broken); use &lt;CODE&gt;_index_earliest=-5m&lt;/CODE&gt; to be sure that you are looking at newly-indexed events.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 17:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-conf-Timestamp-Not-Parsing/m-p/455148#M78732</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-14T17:43:33Z</dc:date>
    </item>
  </channel>
</rss>

