<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can splunk recognize Chinese character timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538957#M90296</link>
    <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Archive/How-do-I-search-for-Chinese-characters-in-Splunk/m-p/393544" target="_blank"&gt;https://community.splunk.com/t5/Archive/How-do-I-search-for-Chinese-characters-in-Splunk/m-p/393544&lt;/A&gt;&lt;/P&gt;&lt;P&gt;this question seems like a good fit for your case.. maybe, you can create if cases for the AM and PM and then manually do the calculations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/Data/Configurecharactersetencoding" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/Data/Configurecharactersetencoding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;pls check the Chinese character set - "&lt;SPAN&gt;GB_2312-80 (aka, CHINESE, ISO-IR-58, CSISO58GB231280)"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;try to use it and see if it picks up the Chinese&amp;nbsp;characters.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;on this question,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/how-to-recognize-timestamp-with-Chinese-character/td-p/30576?sort=oldest" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/how-to-recognize-timestamp-with-Chinese-character/td-p/30576?sort=oldest&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;its said that "Currently we do not support Chinese month like 一月, ......十二月.&lt;BR /&gt;SPL-67688 has been created for getting supported, will be fixed in the later version."... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but searching for "SPL-67688" fails, not sure of how to proceed. if the above two ideas didnt work, you should check with Splunk Support only.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Feb 2021 10:04:05 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2021-02-08T10:04:05Z</dc:date>
    <item>
      <title>Can splunk recognize Chinese character timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538918#M90294</link>
      <description>&lt;P&gt;&lt;SPAN&gt;1.How can I extract timestamp to correct time as following ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2020/12/29 下午 02:39:45&amp;nbsp; &amp;nbsp; "下午" means&amp;nbsp; PM&amp;nbsp; &amp;nbsp;==&amp;gt;&amp;nbsp;2020/12/29&amp;nbsp; 14:39:45&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2020/12/29 上午 05:15:08&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;"上午" means AM&amp;nbsp; &amp;nbsp;==&amp;gt;&amp;nbsp;2020/12/29&amp;nbsp; 05:15:08&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.If splunk can't recognize Chinese character, I change the time "下午" to PM and&amp;nbsp; "上午" to AM manually, can I&amp;nbsp;extract timestamp as following?&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; I use "%Y/%m/%d %p %I:%M:%S" to extract time, but it fails.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2020/12/29 PM 02:39:45&amp;nbsp; &amp;nbsp;==&amp;gt;&amp;nbsp;2020/12/29&amp;nbsp; 14:39:45&amp;nbsp;&lt;BR /&gt;2020/12/29 AM 05:15:08&amp;nbsp; &amp;nbsp;==&amp;gt;&amp;nbsp;2020/12/29&amp;nbsp; 05:15:08&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 06:45:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538918#M90294</guid>
      <dc:creator>123tk</dc:creator>
      <dc:date>2021-02-08T06:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk recognize Chinese character timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538956#M90295</link>
      <description>&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;'上午'　→　&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;\x{&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;4e0a&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;}\x{&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;5348&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;}&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;'下午'　→　\x{&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;4e0b}\x{5348}&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;please modify datetime.xml&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/Data/Configuredatetimexml" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/Data/Configuredatetimexml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;define name="_ampm" extract="ampm"&amp;gt;
        &amp;lt;text&amp;gt;&amp;lt;![CDATA[([ap]m(?:[^A-Za-z0-9]|$)|[\x{4E0A}\x{4E0B}]\x{5348})?]]&amp;gt;&amp;lt;/text&amp;gt;
&amp;lt;/define&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;I wrote that, but there is a setting.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT = %Y/%m/%d %p %I:%M:%S&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;nbsp;sample:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw
| eval _raw="2020/12/29 下午 02:39:45    \"下午\" means  PM   ==&amp;gt; 2020/12/29  14:39:45 
2020/12/29 上午 05:15:08      \"上午\" means AM   ==&amp;gt; 2020/12/29  05:15:08"
| multikv noheader=t
| rex "(?&amp;lt;time&amp;gt;.*?)\""
| eval time_epoch=strptime(time,"%Y/%m/%d %p %I:%M:%S")
| convert ctime(time_epoch) as time1
| table time time_epoch time1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;well, AM/PM is %P not %p&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 10:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538956#M90295</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-02-08T10:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk recognize Chinese character timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538957#M90296</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Archive/How-do-I-search-for-Chinese-characters-in-Splunk/m-p/393544" target="_blank"&gt;https://community.splunk.com/t5/Archive/How-do-I-search-for-Chinese-characters-in-Splunk/m-p/393544&lt;/A&gt;&lt;/P&gt;&lt;P&gt;this question seems like a good fit for your case.. maybe, you can create if cases for the AM and PM and then manually do the calculations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/Data/Configurecharactersetencoding" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/Data/Configurecharactersetencoding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;pls check the Chinese character set - "&lt;SPAN&gt;GB_2312-80 (aka, CHINESE, ISO-IR-58, CSISO58GB231280)"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;try to use it and see if it picks up the Chinese&amp;nbsp;characters.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;on this question,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/how-to-recognize-timestamp-with-Chinese-character/td-p/30576?sort=oldest" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/how-to-recognize-timestamp-with-Chinese-character/td-p/30576?sort=oldest&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;its said that "Currently we do not support Chinese month like 一月, ......十二月.&lt;BR /&gt;SPL-67688 has been created for getting supported, will be fixed in the later version."... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but searching for "SPL-67688" fails, not sure of how to proceed. if the above two ideas didnt work, you should check with Splunk Support only.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 10:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/538957#M90296</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2021-02-08T10:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk recognize Chinese character timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/539082#M90311</link>
      <description>&lt;LI-CODE lang="markup"&gt;&amp;lt;datetime&amp;gt;
    &amp;lt;define name="ccm_1_date" extract="year,month,day"&amp;gt;
        &amp;lt;text&amp;gt;&amp;lt;![CDATA[\s(\d{4})/(\d{2})/(\d{1-2})]]&amp;gt;&amp;lt;/text&amp;gt;
    &amp;lt;/define&amp;gt;
&amp;lt;define name="_ampm" extract="ampm"&amp;gt;
        &amp;lt;text&amp;gt;&amp;lt;![CDATA[([ap]m(?:[^A-Za-z0-9]|$)|[\x{4E0A}\x{4E0B}]\x{5348})?]]&amp;gt;&amp;lt;/text&amp;gt;
&amp;lt;/define&amp;gt;
  &amp;lt;define name="ccm_1_time" extract="hour,minute,second"&amp;gt;
     &amp;lt;text&amp;gt;&amp;lt;![CDATA[\w{2}s(\d{2}):(\d{2}):(\d{2})]]&amp;gt;&amp;lt;/text&amp;gt;
  &amp;lt;/define&amp;gt;

&amp;lt;timePatterns&amp;gt;
      &amp;lt;use name="ccm_1_time"/&amp;gt;
&amp;lt;/timePatterns&amp;gt;
&amp;lt;datePatterns&amp;gt;
      &amp;lt;use name="ccm_1_date"/&amp;gt; 
&amp;lt;/datePatterns&amp;gt;

&amp;lt;/datetime&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;hi thanks you for the reply&lt;/P&gt;&lt;P&gt;I found out that if the time is "2020/12/1 12:01:46 上午" the system can recognize Chinese and extract the time correctly to "&lt;SPAN&gt;20/12/01 0:01:46.000"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, the system cannot extract&amp;nbsp; "2020/12/1 上午 12:01:46 " correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I try to write the datetime2.xml like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it fails.......&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 02:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/539082#M90311</guid>
      <dc:creator>123tk</dc:creator>
      <dc:date>2021-02-09T02:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk recognize Chinese character timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/539112#M90322</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I spent the whole day and finally found out the solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%Y/%m/%d %P %I:%M:%S&lt;/LI-CODE&gt;&lt;P&gt;use above to define timestamp, ALSO you have to clarify the name of the time(order_date)&lt;/P&gt;&lt;P&gt;for example as the csv file:&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;order_date&amp;nbsp; &amp;nbsp;product&lt;/P&gt;&lt;P&gt;2020/12/1 上午 11:01:46&amp;nbsp; &amp;nbsp;cups&lt;/P&gt;&lt;P&gt;2020/12/16 下午 04:01:46&amp;nbsp; unberllas&lt;/P&gt;&lt;P&gt;and as the splunk ingests the file, you will get&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;_time&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2020/12/1&amp;nbsp; 11:01:46&lt;/P&gt;&lt;P&gt;2020/12/16&amp;nbsp; 16:01:46&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 08:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-splunk-recognize-Chinese-character-timestamp/m-p/539112#M90322</guid>
      <dc:creator>123tk</dc:creator>
      <dc:date>2021-02-09T08:47:22Z</dc:date>
    </item>
  </channel>
</rss>

