<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting metrics timestamp in future in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-metrics-timestamp-in-future/m-p/512020#M86902</link>
    <description>&lt;P&gt;Hello, I am trying to get metrics from RouterOS using scripting (logs are forwarded using UDP)&lt;/P&gt;&lt;P&gt;I end up with all timestamps 3 hours in the future (tried adding TZ = GMT, didn't help)&lt;/P&gt;&lt;P&gt;I created a custom format like this: `script, debug &amp;lt;TIMESTAMP&amp;gt; metric_name=firewall_rule &amp;lt;OTHER.DIMS..&amp;gt; packets=100 bytes = 11`&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;script, debug aug/01/2020 17:35:14 +03:00:00 metric_name=firewall_rule rule=dummy bytes=12345 packet=40&lt;/P&gt;&lt;P&gt;I also tried doing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval test=strptime("aug/01/2020 17:35:14 +03:00:00", "%b/%d/%Y %T %::z")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I get correct UNIX timestamp in query results&lt;/P&gt;&lt;P&gt;transforms.conf&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[metric-schema:log2metrics_mikrotik_keyvalue]
METRIC-SCHEMA-MEASURES-firewall_rule = packets, bytes&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[log2metrics_mikrotik_keyvalue]
DATETIME_CONFIG = 
LINE_BREAKER = ([\r\n]+)
METRIC-SCHEMA-TRANSFORMS = metric-schema:log2metrics_mikrotik_keyvalue
NO_BINARY_CHECK = true
TRANSFORMS-EXTRACT = field_extraction
category = Metrics
pulldown_type = 1
# RouterOS
# mmm/dd/yyyy HH:MM:SS [+-]TZHH:TZMM:TZSS
TIME_FORMAT = %b/%d/%Y %T %::z
TZ = GMT
disabled = false
SHOULD_LINEMERGE = false
BREAK_ONLY_BEFORE_DATE = 
PREAMBLE_REGEX = script,debug &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 01 Aug 2020 15:10:17 GMT</pubDate>
    <dc:creator>nazar554</dc:creator>
    <dc:date>2020-08-01T15:10:17Z</dc:date>
    <item>
      <title>Getting metrics timestamp in future</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-metrics-timestamp-in-future/m-p/512020#M86902</link>
      <description>&lt;P&gt;Hello, I am trying to get metrics from RouterOS using scripting (logs are forwarded using UDP)&lt;/P&gt;&lt;P&gt;I end up with all timestamps 3 hours in the future (tried adding TZ = GMT, didn't help)&lt;/P&gt;&lt;P&gt;I created a custom format like this: `script, debug &amp;lt;TIMESTAMP&amp;gt; metric_name=firewall_rule &amp;lt;OTHER.DIMS..&amp;gt; packets=100 bytes = 11`&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;script, debug aug/01/2020 17:35:14 +03:00:00 metric_name=firewall_rule rule=dummy bytes=12345 packet=40&lt;/P&gt;&lt;P&gt;I also tried doing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval test=strptime("aug/01/2020 17:35:14 +03:00:00", "%b/%d/%Y %T %::z")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I get correct UNIX timestamp in query results&lt;/P&gt;&lt;P&gt;transforms.conf&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[metric-schema:log2metrics_mikrotik_keyvalue]
METRIC-SCHEMA-MEASURES-firewall_rule = packets, bytes&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[log2metrics_mikrotik_keyvalue]
DATETIME_CONFIG = 
LINE_BREAKER = ([\r\n]+)
METRIC-SCHEMA-TRANSFORMS = metric-schema:log2metrics_mikrotik_keyvalue
NO_BINARY_CHECK = true
TRANSFORMS-EXTRACT = field_extraction
category = Metrics
pulldown_type = 1
# RouterOS
# mmm/dd/yyyy HH:MM:SS [+-]TZHH:TZMM:TZSS
TIME_FORMAT = %b/%d/%Y %T %::z
TZ = GMT
disabled = false
SHOULD_LINEMERGE = false
BREAK_ONLY_BEFORE_DATE = 
PREAMBLE_REGEX = script,debug &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 15:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-metrics-timestamp-in-future/m-p/512020#M86902</guid>
      <dc:creator>nazar554</dc:creator>
      <dc:date>2020-08-01T15:10:17Z</dc:date>
    </item>
  </channel>
</rss>

