<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timestamp issue with firewall logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-issue-with-firewall-logs/m-p/528346#M89081</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;still learning Splunk here and we just started ingesting Fortigate firewall logs. After a recent FortiGate update the logs are coming in all with a timestamp of 5am. The logs are coming in via syslog to a HF. I have tried using&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIME_FORMAT = date=%Y-%m-%d time=%H:%M:%S&lt;BR /&gt;TIME_PREFIX = ^\s*&amp;lt;\d{3}&amp;gt;&lt;/P&gt;&lt;P&gt;which was suggested in another fortigate ticket without any luck. Any help is appreciated.&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class="formated-time"&gt;&lt;SPAN&gt;11/6/20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5:00:00.000 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;lt;&lt;SPAN class="t"&gt;189&lt;/SPAN&gt;&amp;gt;&lt;SPAN class="t"&gt;logver=602055878&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timestamp=1604673601&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tz=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;UTC-5:00&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;devname=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;RNHN-FW1800F&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;devid=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;FG181FTK20900192&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;vd=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;CORP&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;date=2020-11-06&lt;/SPAN&gt; &lt;SPAN class="t"&gt;time=09:40:01&lt;/SPAN&gt; &lt;SPAN class="t"&gt;logid=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;0001000014&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;type=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;traffic&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;subtype=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;local&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;level=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;notice&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;eventtime=1604673601539310045&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tz=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;-0500&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcip=87.251.80.10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;srcport=53887&lt;/SPAN&gt; &lt;SPAN class="t"&gt;srcintf=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;FairPoint_WAN_B&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcintfrole=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;wan&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;dstip=71.181.10.217&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dstport=2256&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dstintf=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;unknown0&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;dstintfrole=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;undefined&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;sessionid=45763314&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proto=6&lt;/SPAN&gt; &lt;SPAN class="t"&gt;action=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;deny&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;policyid=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;policytype=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;local-in-policy&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;service=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;tcp/2256&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;dstcountry=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;United&lt;/SPAN&gt; &lt;SPAN class="t"&gt;States&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srccountry=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;Russian&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Federation&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;trandisp=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;noop&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;app=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;tcp/2256&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;duration=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sentbyte=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rcvdbyte=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sentpkt=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;appcat=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;unscanned&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;crscore=5&lt;/SPAN&gt; &lt;SPAN class="t"&gt;craction=262144&lt;/SPAN&gt; &lt;SPAN class="t"&gt;crlevel=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;low&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;mastersrcmac=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;02:00:40:05:26:15&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcmac=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;02:00:40:05:26:15&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcserver=1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Fri, 06 Nov 2020 16:03:27 GMT</pubDate>
    <dc:creator>tkerr1357</dc:creator>
    <dc:date>2020-11-06T16:03:27Z</dc:date>
    <item>
      <title>Timestamp issue with firewall logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-issue-with-firewall-logs/m-p/528346#M89081</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;still learning Splunk here and we just started ingesting Fortigate firewall logs. After a recent FortiGate update the logs are coming in all with a timestamp of 5am. The logs are coming in via syslog to a HF. I have tried using&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIME_FORMAT = date=%Y-%m-%d time=%H:%M:%S&lt;BR /&gt;TIME_PREFIX = ^\s*&amp;lt;\d{3}&amp;gt;&lt;/P&gt;&lt;P&gt;which was suggested in another fortigate ticket without any luck. Any help is appreciated.&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class="formated-time"&gt;&lt;SPAN&gt;11/6/20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5:00:00.000 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;lt;&lt;SPAN class="t"&gt;189&lt;/SPAN&gt;&amp;gt;&lt;SPAN class="t"&gt;logver=602055878&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timestamp=1604673601&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tz=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;UTC-5:00&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;devname=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;RNHN-FW1800F&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;devid=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;FG181FTK20900192&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;vd=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;CORP&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;date=2020-11-06&lt;/SPAN&gt; &lt;SPAN class="t"&gt;time=09:40:01&lt;/SPAN&gt; &lt;SPAN class="t"&gt;logid=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;0001000014&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;type=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;traffic&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;subtype=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;local&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;level=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;notice&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;eventtime=1604673601539310045&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tz=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;-0500&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcip=87.251.80.10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;srcport=53887&lt;/SPAN&gt; &lt;SPAN class="t"&gt;srcintf=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;FairPoint_WAN_B&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcintfrole=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;wan&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;dstip=71.181.10.217&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dstport=2256&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dstintf=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;unknown0&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;dstintfrole=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;undefined&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;sessionid=45763314&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proto=6&lt;/SPAN&gt; &lt;SPAN class="t"&gt;action=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;deny&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;policyid=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;policytype=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;local-in-policy&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;service=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;tcp/2256&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;dstcountry=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;United&lt;/SPAN&gt; &lt;SPAN class="t"&gt;States&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srccountry=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;Russian&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Federation&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;trandisp=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;noop&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;app=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;tcp/2256&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;duration=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sentbyte=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rcvdbyte=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sentpkt=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;appcat=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;unscanned&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;crscore=5&lt;/SPAN&gt; &lt;SPAN class="t"&gt;craction=262144&lt;/SPAN&gt; &lt;SPAN class="t"&gt;crlevel=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;low&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;mastersrcmac=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;02:00:40:05:26:15&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcmac=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;02:00:40:05:26:15&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;srcserver=1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 06 Nov 2020 16:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-issue-with-firewall-logs/m-p/528346#M89081</guid>
      <dc:creator>tkerr1357</dc:creator>
      <dc:date>2020-11-06T16:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp issue with firewall logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timestamp-issue-with-firewall-logs/m-p/528352#M89082</link>
      <description>&lt;P&gt;The TIME_PREFIX value does not match the example data.&amp;nbsp; Try these settings&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT = %Y-%m-%d time=%H:%M:%S
TIME_PREFIX = date=&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 06 Nov 2020 16:43:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timestamp-issue-with-firewall-logs/m-p/528352#M89082</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-06T16:43:18Z</dc:date>
    </item>
  </channel>
</rss>

