<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Json parsing - Failed to parse timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554230#M91850</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234998"&gt;@shakSplunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from your provided sample json what output you expecting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 09:16:32 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2021-06-03T09:16:32Z</dc:date>
    <item>
      <title>Json parsing - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554045#M91834</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm quite new to splunk. I've been testing the manual upload of the following json file to splunk enterprise. However, I'm getting the error "Failed to parse timestamp" so I'm guessing it's unable to read the timestamp that is available in the json file "date_time". Would anyone be able to help me with this issue, also I am unable to alter the config file (etc/...) so hopefully the solution can be done through the web UI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;JSON input file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;{
    "SVP": {
        "rcc": {
            "application": {
                "ICE13": {
                    "hostname": "218",
                    "domain": "rc",
                    "app_id": "13",
                    "version": "413",
                    "date_time": "29/05/2021"
                },
                "ICE1": {
                    "hostname": "lnxau2004st0218",
                    "domain": "rcc",
                    "app_id": "1",
                    "version": "413",
                    "date_time": "31/05/2021",
                    "UPP": {
                        "hostname": "218",
                        "domain": "rc",
                        "version": "null",
                        "date_time": "29/05/2021"
                    }
                }
            },
            "utility": {
                "ICE13": {
                    "Ctl.sh": {
                        "hostname": "218",
                        "domain": "rc",
                        "version": "144",
                        "date_time": "29/05/2021"
                    }
                },
                "ICE1": {
                    "Ctl.sh": {
                        "hostname": "218",
                        "domain": "rc",
                        "version": "144",
                        "date_time": "31/05/2021"
                    }
                },
                "ICE5": {
                    "Ctl.sh": {
                        "hostname": "218",
                        "domain": "rc",
                        "version": "144",
                        "date_time": "30/05/2021"
                    }
                },
                "ICE9": {
                    "Ctl.sh": {
                        "hostname": "218",
                        "domain": "rc",
                        "version": "144",
                        "date_time": "31/05/2021"
                    }
                },
                "ICE11": {
                    "Ctl.sh": {
                        "hostname": "219",
                        "domain": "rc",
                        "version": "140",
                        "date_time": "30/05/2021"
                    }
                }
            }
        }
    }
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any and all help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 06:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554045#M91834</guid>
      <dc:creator>shakSplunk</dc:creator>
      <dc:date>2021-06-02T06:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Json parsing - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554093#M91836</link>
      <description>&lt;P&gt;What are the props.conf settings for that sourcetype?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 12:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554093#M91836</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-06-02T12:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Json parsing - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554182#M91841</link>
      <description>&lt;P&gt;My props.configs file looks like this:&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;[output_simplified1]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;DATETIME_CONFIG&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;INDEXED_EXTRACTIONS&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;JSON&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;KV_MODE&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;none&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;LINE_BREAKER&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;([\r\n]+)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;NO_BINARY_CHECK&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;category&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;Structured&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;description&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;JavaScript&amp;nbsp;Object&amp;nbsp;Notation&amp;nbsp;format.&amp;nbsp;For&amp;nbsp;more&amp;nbsp;information,&amp;nbsp;visit&amp;nbsp;&lt;A href="http://json.org/" target="_blank" rel="noopener"&gt;http://json.org/&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;disabled&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;false&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;pulldown_type&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;TIME_PREFIX&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;},&lt;SPAN&gt;"date_time"&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;TIME_FORMAT&lt;SPAN&gt;&amp;nbsp;=&amp;nbsp;%d/%m/%Y&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&amp;nbsp;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;What my goal here is to an event for each timestamp, thus 1 event capturing the following information:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;"SVP": {
        "rcc": {
            "application": {
                "ICE13": {
                    "hostname": "218",
                    "domain": "rc",
                    "app_id": "13",
                    "version": "413",
                    "date_time": "29/05/2021"
                }&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;With the next event containing:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;"ICE1": {
                    "hostname": "lnxau2004st0218",
                    "domain": "rcc",
                    "app_id": "1",
                    "version": "413",
                    "date_time": "31/05/2021"​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;with the Application, rcc and SVP upper level keys also attached.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;Essentially every object that has a data_time attribute, it should be turned its own independent event that should be able to be categorised based on the keys. E.g. Filtering based on "application" whilst within SVP.rcc&lt;/P&gt;&lt;P&gt;Is this possible? Is it overcomplicating and consequently should the data structure be altered?&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt; &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 03:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554182#M91841</guid>
      <dc:creator>shakSplunk</dc:creator>
      <dc:date>2021-06-03T03:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Json parsing - Failed to parse timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554230#M91850</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234998"&gt;@shakSplunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from your provided sample json what output you expecting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 09:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Json-parsing-Failed-to-parse-timestamp/m-p/554230#M91850</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-03T09:16:32Z</dc:date>
    </item>
  </channel>
</rss>

