<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time_PREFIX for Props.conf with unstructured text file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557114#M92189</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its bit tricky to find from screenshot only prefix of time you have is space which is \s,&amp;nbsp; you can try something as follows, you shall change other params as well. If your text event having pre-determined spaces before timestamp just use the exact number.. something like if you have fixed 10 spaces \s{10}.&lt;/P&gt;&lt;P&gt;TIME_PREFIX = \s{6,}&lt;/P&gt;&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD = 23&lt;/P&gt;&lt;P&gt;TIME_FORMAT =&amp;nbsp;%Y-%m-%d %H:%M:%S.%3Q&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and accept solution if it helps!&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 05:26:45 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-06-25T05:26:45Z</dc:date>
    <item>
      <title>Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557111#M92188</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;Hi There,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Here is a segment of my sample data . Data is in text format. My Props.conf file has also been provided below. I have some issues to figure out what I would write in TIME_PREFIX for my PROPS.Conf file (please see below). Any help will be highly appreciated, thank you.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malekmo_0-1624595074903.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14809i49E4D7106B3D4D83/image-size/large?v=v2&amp;amp;px=999" role="button" title="malekmo_0-1624595074903.png" alt="malekmo_0-1624595074903.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;SHOULD_LINEMERGE=false&lt;/FONT&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;LINE_BREAKER=([\r\n]+)&lt;/FONT&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;CHARSET=UTF-8&lt;/FONT&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;TIME_PREFIX=&lt;/FONT&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S.%3N&lt;/FONT&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;MAX_TIMESTAMP_LOOKAHEAD=18&lt;/FONT&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Thank you and Regards,&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 04:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557111#M92188</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-06-25T04:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557114#M92189</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its bit tricky to find from screenshot only prefix of time you have is space which is \s,&amp;nbsp; you can try something as follows, you shall change other params as well. If your text event having pre-determined spaces before timestamp just use the exact number.. something like if you have fixed 10 spaces \s{10}.&lt;/P&gt;&lt;P&gt;TIME_PREFIX = \s{6,}&lt;/P&gt;&lt;P&gt;MAX_TIMESTAMP_LOOKAHEAD = 23&lt;/P&gt;&lt;P&gt;TIME_FORMAT =&amp;nbsp;%Y-%m-%d %H:%M:%S.%3Q&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and accept solution if it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 05:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557114#M92189</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-25T05:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557117#M92191</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi venkatasri,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your quick response, appreciated. Unfortunately, it's not a fixed space...it varies from 2 to 20+.... please see another segment of sample data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malekmo_0-1624599332997.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14810iBBE73850FCBE431E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="malekmo_0-1624599332997.png" alt="malekmo_0-1624599332997.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 05:36:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557117#M92191</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-06-25T05:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557119#M92192</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not find a possibility to set TIME_PREFIX for your case i would rather leave the timestamp detection to Splunk, splunk is able to detect if you do not set any TIME* related conf.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 05:53:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557119#M92192</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-25T05:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557120#M92193</link>
      <description>&lt;P&gt;Then what would be my PROPS.CONF file........&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557120#M92193</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-06-25T06:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557122#M92194</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;Test with following and see how timestamp is being set by Splunk. Additionally you can set TZ which is a timezone if your event timezone is different from indexer.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and accept solution if it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:35:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557122#M92194</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-25T06:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557125#M92196</link>
      <description>&lt;P&gt;Thank you so much, appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557125#M92196</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-06-25T06:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Time_PREFIX for Props.conf with unstructured text file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557129#M92197</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;please accept solution if it helps!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 07:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-PREFIX-for-Props-conf-with-unstructured-text-file/m-p/557129#M92197</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-25T07:16:22Z</dc:date>
    </item>
  </channel>
</rss>

