<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Timestamp recognition in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527661#M88988</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No heavy forwarder, just direct connect from UF to Indexer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Nov 2020 08:30:52 GMT</pubDate>
    <dc:creator>kcchu01</dc:creator>
    <dc:date>2020-11-03T08:30:52Z</dc:date>
    <item>
      <title>Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527626#M88978</link>
      <description>&lt;P&gt;I am trying to monitor the log file and index to Splunk with the following log format.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;02/11/2020&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;16:09:02&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;test-xxxxx&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;DISCONNECT ....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;The date format is in DD/MM/YYYY, I added the following stanza in the $SPLUNK/etc/system/local/props.conf of the indexer&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[testsourcetype]&lt;/P&gt;&lt;P&gt;TIME_FORMAT = %d/%m/%Y,%H:%M:%S&lt;/P&gt;&lt;P&gt;However the log still not able to be indexed to Splunk, are there anything I missed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 03:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527626#M88978</guid>
      <dc:creator>kcchu01</dc:creator>
      <dc:date>2020-11-03T03:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527653#M88986</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155606"&gt;@kcchu01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only one question: is there any Heavy Forwatders between the source and the Indexer?&lt;/P&gt;&lt;P&gt;If yes, you have to put this props.conf (also) on Heavy Forwarder.&lt;/P&gt;&lt;P&gt;then add to your props.conf&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_PREFIX = ^&lt;/LI-CODE&gt;&lt;P&gt;to be sure that Splunk takes the correct timestamp.&lt;/P&gt;&lt;P&gt;Another final question: what's the error you have?&lt;/P&gt;&lt;P&gt;Only one final hint. if a test installation it could be also ok, but usually it's a best practice not to put props.conf in $SPLUNK_HOME/etc/system/local, but it in an App or in Technical Add-On (TA).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 07:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527653#M88986</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-11-03T07:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527661#M88988</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No heavy forwarder, just direct connect from UF to Indexer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 08:30:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527661#M88988</guid>
      <dc:creator>kcchu01</dc:creator>
      <dc:date>2020-11-03T08:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527666#M88990</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155606"&gt;@kcchu01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what's the error you have?&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 08:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527666#M88990</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-11-03T08:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527831#M89004</link>
      <description>&lt;P&gt;No new log found after modified the props.conf&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 01:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527831#M89004</guid>
      <dc:creator>kcchu01</dc:creator>
      <dc:date>2020-11-04T01:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527885#M89011</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155606"&gt;@kcchu01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you updated your props.conf on Indexer,&lt;/LI&gt;&lt;LI&gt;then you restarted Splunk on Indexers,&lt;/LI&gt;&lt;LI&gt;your source file is changed in the meanwhile;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is this correct?&lt;/P&gt;&lt;P&gt;Check the last point because the props.conf is correct and located in the correct point.&lt;/P&gt;&lt;P&gt;But Splunk doesn't index twice a log.&lt;/P&gt;&lt;P&gt;For test, you could add to inputs.conf, in the stanza of the test input also&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;in this way, changing the file name, you can index it more times.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 11:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/527885#M89011</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-11-04T11:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/528767#M89117</link>
      <description>&lt;P&gt;Hi, the log can be indexed again after following your method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 01:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/528767#M89117</guid>
      <dc:creator>kcchu01</dc:creator>
      <dc:date>2020-11-10T01:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp recognition</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/528782#M89118</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155606"&gt;@kcchu01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 07:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-recognition/m-p/528782#M89118</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-11-10T07:11:33Z</dc:date>
    </item>
  </channel>
</rss>

