<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk_TA_Windows - script:installedapps timestamp issues? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-Windows-script-installedapps-timestamp-issues/m-p/529645#M89217</link>
    <description>&lt;P&gt;All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought I posted this before, but can't find it in my history.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing alerts in my Splunk logs statin that the I am getting data from the future on my sourcetype&amp;nbsp; script:installedapps. It's default and unmodified from the Splunk_TA_Window standard.&lt;/P&gt;&lt;P&gt;From there I did notice that _indextime and _time were off a bit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look at props.conf provided by Splunk_TA_Windows it has no time stamp recognition. Is there a reason for this? Should I go ahead and add it or is there a trick for this I am missing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;-Daniel&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Nov 2020 23:29:02 GMT</pubDate>
    <dc:creator>daniel333</dc:creator>
    <dc:date>2020-11-16T23:29:02Z</dc:date>
    <item>
      <title>Splunk_TA_Windows - script:installedapps timestamp issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-Windows-script-installedapps-timestamp-issues/m-p/529645#M89217</link>
      <description>&lt;P&gt;All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought I posted this before, but can't find it in my history.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing alerts in my Splunk logs statin that the I am getting data from the future on my sourcetype&amp;nbsp; script:installedapps. It's default and unmodified from the Splunk_TA_Window standard.&lt;/P&gt;&lt;P&gt;From there I did notice that _indextime and _time were off a bit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look at props.conf provided by Splunk_TA_Windows it has no time stamp recognition. Is there a reason for this? Should I go ahead and add it or is there a trick for this I am missing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;-Daniel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 23:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-Windows-script-installedapps-timestamp-issues/m-p/529645#M89217</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2020-11-16T23:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_Windows - script:installedapps timestamp issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-Windows-script-installedapps-timestamp-issues/m-p/529649#M89218</link>
      <description>&lt;P&gt;So I went ahead and created a basic props.conf per my undertanding of best practice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My latency between time and indexed time was about -80second on this sourcetype. After adding the below props.conf to a local override I am now getting closer to 10 seconds.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Didn't think props.conf would so dramatically impact a single sourcetype like that, but I guess it could? Either way no longer getting the data from the future error either.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;# props.conf&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;[Script:InstalledApps]&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;pulldown_type = true&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;category = Windows&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;description = List Installed Apps&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;### Index time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;# Input queue - event_breaker processed at the UF as well as IDX&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EVENT_BREAKER_ENABLE = true&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EVENT_BREAKER = ([\r\n]+)\d{4}\-\d{2}\-\d{2}\s+\d{1,2}:\d{2}:\d{2}.\d{3}&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NO_BINARY_CHECK = True&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;CHARSET = UTF-8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;DATETIME_CONFIG=&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;TIME_PREFIX= ^&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;MAX_TIMESTAMP_LOOKAHEAD= 24&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;TIME_FORMAT= %Y-%m-%d %H:%M:%S.%3Q&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;MAX_DAYS_AGO = 1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;MAX_DAYS_HENCE = 2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;# Typing queue&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;ANNOTATE_PUNCT = False&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;# Indexing queue&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;SEGMENTATION = indexing&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;# Search time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EVAL-data_classification = "Proprietary"&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 17 Nov 2020 00:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-Windows-script-installedapps-timestamp-issues/m-p/529649#M89218</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2020-11-17T00:03:34Z</dc:date>
    </item>
  </channel>
</rss>

