<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can splunk  extract timestamp till nano seconds in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-extract-timestamp-till-nano-seconds/m-p/520358#M87966</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I am trying to extract timestamp including nanoseconds but I am able to extract only 7 digits of nanoseconds though I used %9N in TIME_FORMAT.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Below is my sample event-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;10,11/03/20 04:00:00.000000010,11/03/20,04:00:00,Zx: 6037,04:00:00,48d4c21c3014850838840a460424c05b20412128053ce6074720006e00f1ff5500000000000000,Mod=2,AckReq=0,RtBits=0,MsgSeq=35,OnRte=1,Id=46,VId=6037&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Below is my props.conf -&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[abc_logs_st]
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = false
NO_BINARY_CHECK = true
category = Custom
pulldown_type = 1
disabled = false
TIME_PREFIX = ^\d+\,
MAX_TIMESTAMP_LOOKAHEAD = 30
TIME_FORMAT = %m/%d/%y %H:%M:%S.%9N&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why Splunk is considering only 7 digits after decimal..Is this bug in Splunk?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 17:14:08 GMT</pubDate>
    <dc:creator>ips_mandar</dc:creator>
    <dc:date>2020-09-18T17:14:08Z</dc:date>
    <item>
      <title>Can splunk  extract timestamp till nano seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-extract-timestamp-till-nano-seconds/m-p/520358#M87966</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I am trying to extract timestamp including nanoseconds but I am able to extract only 7 digits of nanoseconds though I used %9N in TIME_FORMAT.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Below is my sample event-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;10,11/03/20 04:00:00.000000010,11/03/20,04:00:00,Zx: 6037,04:00:00,48d4c21c3014850838840a460424c05b20412128053ce6074720006e00f1ff5500000000000000,Mod=2,AckReq=0,RtBits=0,MsgSeq=35,OnRte=1,Id=46,VId=6037&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Below is my props.conf -&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[abc_logs_st]
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = false
NO_BINARY_CHECK = true
category = Custom
pulldown_type = 1
disabled = false
TIME_PREFIX = ^\d+\,
MAX_TIMESTAMP_LOOKAHEAD = 30
TIME_FORMAT = %m/%d/%y %H:%M:%S.%9N&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why Splunk is considering only 7 digits after decimal..Is this bug in Splunk?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 17:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-extract-timestamp-till-nano-seconds/m-p/520358#M87966</guid>
      <dc:creator>ips_mandar</dc:creator>
      <dc:date>2020-09-18T17:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk  extract timestamp till nano seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-extract-timestamp-till-nano-seconds/m-p/520362#M87967</link>
      <description>Yes splunk can extract it to ms. Your data an props seems to be correct. You can test it with splunk by trying to add this data with splunk and use Setyings -&amp;gt; add data -&amp;gt; files and directories -&amp;gt; monitor. Then you can evaluate/check that props with your data and try to find what needs to change.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 18 Sep 2020 17:43:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-extract-timestamp-till-nano-seconds/m-p/520362#M87967</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-18T17:43:56Z</dc:date>
    </item>
  </channel>
</rss>

